IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-50945 MED 6.2 ibm common_licensing IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. 0.1%
CVE-2023-45702 MED 6.2 hcltechsw hcl_launch An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.. 0.2%
CVE-2023-36558 MED 6.2 microsoft .net ASP.NET Core Security Feature Bypass Vulnerability 1.1%
CVE-2023-36042 MED 6.2 microsoft visual_studio_2019 Visual Studio Denial of Service Vulnerability 0.8%
CVE-2023-36016 MED 6.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.3%
CVE-2023-35391 MED 6.2 microsoft .net ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability 1.9%
CVE-2023-35341 MED 6.2 microsoft windows_10_1507 Microsoft DirectMusic Information Disclosure Vulnerability 0.5%
CVE-2023-33842 MED 6.2 ibm spss_modeler IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server SSL key which could allow a local user to decrypt and obtain sensitive information. IBM X-Force ID: 256117. 0.2%
CVE-2023-33832 MED 6.2 ibm spectrum_protect_client IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012. 0.1%
CVE-2023-3108 MED 6.2 linux linux_kernel A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system. 0.2%
CVE-2023-28514 MED 6.2 ibm mq IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398. 0.2%
CVE-2023-28269 MED 6.2 microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability 0.6%
CVE-2023-28249 MED 6.2 microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability 0.6%
CVE-2023-24964 MED 6.2 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. 0.1%
CVE-2023-24934 MED 6.2 microsoft malware_protection_platform Microsoft Defender Security Feature Bypass Vulnerability 0.5%
CVE-2023-22878 MED 6.2 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373. 0.1%
CVE-2023-21697 MED 6.2 microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability 0.5%
CVE-2023-20199 MED 6.2 cisco duo A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco 0.3%
CVE-2022-48646 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sfc/siena: fix null pointer dereference in efx_hard_start_xmit Like in previous patch for sfc, prevent potential (but unlikely) NULL pointer dereference. 0.2%
CVE-2022-48635 MED 6.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fsdax: Fix infinite loop in dax_iomap_rw() I got an infinite loop and a WARNING report when executing a tail command in virtiofs. WARNING: CPU: 10 PID: 964 at fs/iomap/iter.c:34 iomap_ite 0.2%
CVE-2022-43949 MED 6.2 fortinet fortisiem A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods. 0.4%
CVE-2022-43930 MED 6.2 ibm db2 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677. 0.5%
CVE-2022-43875 MED 6.2 ibm financial_transaction_manager IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034. 0.2%
CVE-2022-35829 MED 6.2 microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability 19.9%
CVE-2022-35776 MED 6.2 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Denial of Service Vulnerability 0.8%