57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.588 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-32037 | MED 6.5 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-32035 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-32034 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-32032 | MED 6.5 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-31101 | MED 6.5 | apache inlong Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upg | 1.1% | — |
| CVE-2023-31018 | MED 6.5 | nvidia virtual_gpu NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service. | 0.2% | — |
| CVE-2023-30575 | MED 6.5 | apache guacamole Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through specially-crafted data. | 1.0% | — |
| CVE-2023-30456 | MED 6.5 | linux linux_kernel An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4. | 0.5% | — |
| CVE-2023-29369 | MED 6.5 | microsoft windows_server_2012 Remote Procedure Call Runtime Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-29352 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-29324 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2023-29260 | MED 6.5 | ibm sterling_connect\ IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IB | 0.3% | — |
| CVE-2023-29179 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests. | 2.5% | — |
| CVE-2023-28981 | MED 6.5 | juniper junos An Improper Input Validation vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If the receipt of router advertisements is enabled on an interface and a | 0.3% | — |
| CVE-2023-28970 | MED 6.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a specific packet to the d | 0.3% | — |
| CVE-2023-28965 | MED 6.5 | juniper junos An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these packets will create | 0.6% | — |
| CVE-2023-28959 | MED 6.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on QFX10002 allows an unauthenticated, adjacent attacker on the local broadcast domain sending a malformed packet to the device, causing all | 0.3% | — |
| CVE-2023-28312 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Information Disclosure Vulnerability | 1.5% | — |
| CVE-2023-28267 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.1% | — |
| CVE-2023-28158 | MED 6.5 | apache archiva Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user. | 1.2% | — |
| CVE-2023-27873 | MED 6.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654. | 0.8% | — |
| CVE-2023-27859 | MED 6.5 | ibm db2 IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file | 1.0% | — |
| CVE-2023-26589 | MED 6.5 | intel aptio_v_uefi_firmware_integrator_tools Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-25753 | MED 6.5 | apache shenyu There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl paramet | 0.8% | — |
| CVE-2023-25738 | MED 6.5 | mozilla firefox Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects | 0.6% | — |