IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.706 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2014-0196 MED 5.5 canonical ubuntu_linux The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privi 22.5%
CVE-2010-3904 HIGH 7.8 canonical ubuntu_linux The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via cr 14.6%
CVE-2023-29336 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 40.9%
CVE-2021-45046 CRIT 9.0 ransomware apache log4j It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default 100.0%
CVE-2017-6742 HIGH 8.8 cisco ios A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi 21.4%
CVE-2023-28252 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 49.0%
CVE-2019-1388 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. 8.6%
CVE-2023-0266 HIGH 7.9 debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W 3.7%
CVE-2013-3163 HIGH 8.8 microsoft internet_explorer Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013 70.7%
CVE-2023-24880 MED 4.4 ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability 78.2%
CVE-2023-23397 CRIT 9.8 microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability 97.4%
CVE-2022-41328 MED 6.7 fortinet fortios A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlyin 12.3%
CVE-2020-5741 HIGH 7.2 plex media_server Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. 72.9%
CVE-2022-33891 HIGH 8.8 apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht 93.1%
CVE-2022-47986 CRIT 9.8 ransomware ibm aspera_faspex IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to ex 100.0%
CVE-2023-23376 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 10.9%
CVE-2023-21823 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability 5.6%
CVE-2023-21715 HIGH 7.3 microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability 12.0%
CVE-2015-2291 HIGH 7.8 ransomware intel ethernet_diagnostics_driver_iqvw32.sys (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8 9.0%
CVE-2023-21674 HIGH 8.8 microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 41.8%
CVE-2022-41080 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 77.3%
CVE-2022-44698 MED 5.4 ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability 76.3%
CVE-2022-42475 CRIT 9.8 ransomware fortinet fortios A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote u 99.5%
CVE-2022-27518 CRIT 9.8 citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution 6.9%
CVE-2022-4135 CRIT 9.6 google chrome Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 31.9%