IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-40791 MED 6.3 linux linux_kernel extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. 0.4%
CVE-2023-40610 MED 6.3 apache superset Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker usin 1.3%
CVE-2023-36888 MED 6.3 microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Tampering Vulnerability 0.6%
CVE-2023-36869 MED 6.3 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 0.7%
CVE-2023-33156 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0.3%
CVE-2023-33132 MED 6.3 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 0.9%
CVE-2023-2971 MED 6.3 typora typora Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdo 0.5%
CVE-2023-28071 MED 6.3 dell alienware_update Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folde 0.2%
CVE-2023-27869 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named tr 1.6%
CVE-2023-27868 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially c 1.6%
CVE-2023-27867 MED 6.3 ibm db2 IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an 1.6%
CVE-2023-25197 MED 6.3 apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components.   This issue affects apache finera 1.1%
CVE-2023-24490 MED 6.3 citrix linux_virtual_delivery_agent Users with only access to launch VDA applications can launch an unauthorized desktop 0.3%
CVE-2023-24487 MED 6.3 citrix application_delivery_controller Arbitrary file read in Citrix ADC and Citrix Gateway  1.1%
CVE-2023-23389 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0.3%
CVE-2023-21725 MED 6.3 microsoft windows_malicious_software_removal_tool Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability 0.4%
CVE-2023-20862 MED 6.3 netapp active_iq_unified_manager In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly sa 0.6%
CVE-2023-20274 MED 6.3 cisco appdynamics A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the PHP Agent Installer on 0.2%
CVE-2023-20123 MED 6.3 cisco duo A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access 0.2%
CVE-2023-20016 MED 6.3 cisco fxos A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the 0.1%
CVE-2023-1855 MED 6.3 debian debian_linux A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even l 0.2%
CVE-2023-1611 MED 6.3 fedoraproject fedora A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea 0.2%
CVE-2023-0041 MED 6.3 ibm security_guardium IBM Security Guardium 11.5 could allow a user to take over another user's session due to insufficient session expiration. IBM X-Force ID: 243657. 0.5%
CVE-2023-0006 MED 6.3 paloaltonetworks globalprotect A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition. 0.1%
CVE-2022-47984 MED 6.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. 0.7%