IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-32046 HIGH 7.8 microsoft windows_10_1507 Windows MSHTML Platform Elevation of Privilege Vulnerability 10.0%
CVE-2023-32029 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 53.5%
CVE-2023-32028 HIGH 7.8 microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 0.7%
CVE-2023-32027 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.6%
CVE-2023-32026 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.7%
CVE-2023-32025 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.6%
CVE-2023-32018 HIGH 7.8 microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability 0.7%
CVE-2023-32017 HIGH 7.8 microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability 0.5%
CVE-2023-32012 HIGH 7.8 microsoft windows_10_21h2 Windows Container Manager Service Elevation of Privilege Vulnerability 0.5%
CVE-2023-32008 HIGH 7.8 microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2023-3181 HIGH 7.8 splashtop mirroring360_receiver The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system rebo 0.2%
CVE-2023-31436 HIGH 7.8 linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. 0.6%
CVE-2023-31248 HIGH 7.8 canonical ubuntu_linux Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace 2.1%
CVE-2023-31132 HIGH 7.8 cacti cacti Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files 0.4%
CVE-2023-3111 HIGH 7.8 debian debian_linux A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). 0.4%
CVE-2023-31102 HIGH 7.8 7-zip 7-zip Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. 57.1%
CVE-2023-31019 HIGH 7.8 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonati 0.2%
CVE-2023-31017 HIGH 7.8 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, esca 0.2%
CVE-2023-3090 HIGH 7.8 debian debian_linux A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is 0.5%
CVE-2023-30601 HIGH 7.8 apache cassandra Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This issue affects Apache Cassandra: from 4.0.0 through 4.0.9, from 4.1.0 through 4.1.1. WORKAROUND The vulnerability 0.3%
CVE-2023-2939 HIGH 7.8 google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium) 0.5%
CVE-2023-29371 HIGH 7.8 microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability 5.4%
CVE-2023-29370 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.7%
CVE-2023-29367 HIGH 7.8 microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability 0.7%
CVE-2023-29366 HIGH 7.8 microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability 0.7%