57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-45725 | MED 5.7 | apache couchdb Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. These design document functions are: * list * show * rewrite * update An attacker | 1.2% | — |
| CVE-2023-36777 | MED 5.7 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 81.2% | — |
| CVE-2023-35838 | MED 5.7 | wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected | 0.7% | — |
| CVE-2023-28401 | MED 5.7 | intel arc_a_graphics Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28261 | MED 5.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-2737 | MED 5.7 | thalesgroup safenet_authentication_service Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation. | 0.1% | — |
| CVE-2023-26020 | MED 5.7 | craftercms crafter_cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1. | 0.4% | — |
| CVE-2023-23784 | MED 5.7 | fortinet fortiweb A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests. | 0.6% | — |
| CVE-2023-23039 | MED 5.7 | linux linux_kernel An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_rem | 0.2% | — |
| CVE-2023-21693 | MED 5.7 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-20135 | MED 5.7 | cisco ios_xr A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition w | 0.1% | — |
| CVE-2023-1206 | MED 5.7 | fedoraproject fedora A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of | 0.5% | — |
| CVE-2022-30223 | MED 5.7 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22711 | MED 5.7 | microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-20787 | MED 5.7 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request for | 0.4% | — |
| CVE-2021-42288 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2021-41355 | MED 5.7 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 20.3% | — |
| CVE-2021-38632 | MED 5.7 | microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-34466 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-33114 | MED 5.7 | intel ac_1550_firmware Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access. | 0.5% | — |
| CVE-2021-31965 | MED 5.7 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 4.5% | — |
| CVE-2021-28444 | MED 5.7 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2021-27079 | MED 5.7 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-24114 | MED 5.7 | microsoft teams Microsoft Teams iOS Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-1708 | MED 5.7 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 3.4% | — |