57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-25590 | HIGH 7.8 | arubanetworks clearpass_policy_manager A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on | 0.2% | — |
| CVE-2023-25515 | HIGH 7.8 | nvidia cloud_gaming NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure. | 0.2% | — |
| CVE-2023-25148 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attac | 0.4% | — |
| CVE-2023-25146 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped | 0.4% | — |
| CVE-2023-25145 | HIGH 7.8 | trendmicro apex_one A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the | 0.4% | — |
| CVE-2023-25144 | HIGH 7.8 | trendmicro apex_one An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. | 0.3% | — |
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24949 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 24.6% | — |
| CVE-2023-24946 | HIGH 7.8 | microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-24930 | HIGH 7.8 | microsoft onedrive Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-24912 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2023-24910 | HIGH 7.8 | microsoft 365 Windows Graphics Component Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-24905 | HIGH 7.8 | microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24902 | HIGH 7.8 | microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability | 5.1% | — |
| CVE-2023-24897 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-24895 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-24893 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-24671 | HIGH 7.8 | vxsearch vx_search VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file. | 0.4% | — |
| CVE-2023-24491 | HIGH 7.8 | citrix secure_access_client A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privilege | 0.2% | — |
| CVE-2023-24485 | HIGH 7.8 | citrix workspace Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | 0.2% | — |
| CVE-2023-24483 | HIGH 7.8 | citrix virtual_apps_and_desktops A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | 0.3% | — |
| CVE-2023-24068 | HIGH 7.8 | signal signal-desktop Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's abili | 0.4% | — |
| CVE-2023-23782 | HIGH 7.8 | fortinet fortiweb A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically cr | 0.2% | — |
| CVE-2023-23559 | HIGH 7.8 | debian debian_linux In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition. | 0.3% | — |
| CVE-2023-23423 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |