57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21561 | HIGH 7.8 | microsoft windows_10_1607 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-21558 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-21552 | HIGH 7.8 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2023-21551 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-21541 | HIGH 7.8 | microsoft windows_10_1607 Windows Task Scheduler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21537 | HIGH 7.8 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-21528 | HIGH 7.8 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2023-21524 | HIGH 7.8 | microsoft windows_10_1607 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-2124 | HIGH 7.8 | debian debian_linux An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to crash or potentially escalate their privileges on the system. | 0.5% | — |
| CVE-2023-20871 | HIGH 7.8 | vmware fusion VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system. | 0.4% | — |
| CVE-2023-20562 | HIGH 7.8 | amd amd_uprof Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution. | 1.0% | — |
| CVE-2023-20224 | HIGH 7.8 | cisco thousandeyes_enterprise_agent A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validat | 0.4% | — |
| CVE-2023-20178 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The | 5.4% | — |
| CVE-2023-2007 | HIGH 7.8 | debian debian_linux The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute | 0.3% | — |
| CVE-2023-20065 | HIGH 7.8 | cisco ios_xe A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted a | 0.2% | — |
| CVE-2023-20035 | HIGH 7.8 | cisco ios_xe_sd-wan A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privi | 0.2% | — |
| CVE-2023-1872 | HIGH 7.8 | debian debian_linux A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation. The io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race conditi | 0.3% | — |
| CVE-2023-1829 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting | 1.0% | — |
| CVE-2023-1670 | HIGH 7.8 | linux linux_kernel A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | 0.3% | — |
| CVE-2023-1295 | HIGH 7.8 | linux linux_kernel A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf2 | 0.2% | — |
| CVE-2023-1281 | HIGH 7.8 | linux linux_kernel Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the de | 0.3% | — |
| CVE-2023-1252 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with the overlay FS usage. This flaw allows a local user to crash or potentially escalate their privileges on the system. Only | 0.2% | — |
| CVE-2023-1118 | HIGH 7.8 | linux linux_kernel A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | 0.3% | — |
| CVE-2023-1078 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `stru | 0.2% | — |
| CVE-2023-1017 | HIGH 7.8 | microsoft windows_10_1507 An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of s | 1.3% | — |