58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23407 | HIGH 7.1 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-23398 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Spoofing Vulnerability | 0.6% | — |
| CVE-2023-22638 | HIGH 7.1 | fortinet fortinac Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authen | 0.5% | — |
| CVE-2023-21760 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-21752 | HIGH 7.1 | microsoft windows_10 Windows Backup Service Elevation of Privilege Vulnerability | 5.3% | — |
| CVE-2023-21750 | HIGH 7.1 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-21741 | HIGH 7.1 | microsoft 365_apps Microsoft Office Visio Information Disclosure Vulnerability | 1.8% | — |
| CVE-2023-21565 | HIGH 7.1 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 0.9% | — |
| CVE-2023-21564 | HIGH 7.1 | microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability | 0.9% | — |
| CVE-2023-20900 | HIGH 7.1 | debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that targe | 1.3% | — |
| CVE-2023-20253 | HIGH 7.1 | cisco catalyst_sd-wan_manager A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router d | 0.2% | — |
| CVE-2023-20229 | HIGH 7.1 | cisco duo_device_health_application A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system. Thi | 0.4% | — |
| CVE-2023-20168 | HIGH 7.1 | cisco nx-os A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an a | 0.2% | — |
| CVE-2023-1838 | HIGH 7.1 | linux linux_kernel A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information lea | 0.3% | — |
| CVE-2023-1652 | HIGH 7.1 | linux linux_kernel A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem. | 0.2% | — |
| CVE-2023-1380 | HIGH 7.1 | canonical ubuntu_linux A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTR | 16.5% | — |
| CVE-2023-1194 | HIGH 7.1 | fedoraproject fedora An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check o | 1.1% | — |
| CVE-2023-0191 | HIGH 7.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering. | 0.2% | — |
| CVE-2023-0183 | HIGH 7.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of service and data tampering. | 0.2% | — |
| CVE-2023-0181 | HIGH 7.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering. | 0.2% | — |
| CVE-2023-0180 | HIGH 7.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or information disclosure. | 0.2% | — |
| CVE-2022-50551 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac that occurs in BIT(chiprev) when a 'chiprev' provided by the | 0.2% | — |
| CVE-2022-50508 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x0: fix oob access in mt76x0_phy_get_target_power After 'commit ba45841ca5eb ("wifi: mt76: mt76x02: simplify struct mt76x02_rate_power")', mt76x02 relies on ht[0-7] rate_powe | 0.2% | — |
| CVE-2022-50497 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: fix shift-out-of-bounds in check_special_flags UBSAN reported a shift-out-of-bounds warning: left shift of 1 by 31 places cannot be represented in type 'int' Call Trace: <T | 0.2% | — |
| CVE-2022-50490 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Propagate error from htab_lock_bucket() to userspace In __htab_map_lookup_and_delete_batch() if htab_lock_bucket() returns -EBUSY, it will go to next bucket. Going to next bucket may no | 0.2% | — |