56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.706 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2014-0196 | MED 5.5 | canonical ubuntu_linux The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privi | 22.5% | |
| CVE-2010-3904 | HIGH 7.8 | canonical ubuntu_linux The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via cr | 14.6% | |
| CVE-2023-29336 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 40.9% | |
| CVE-2021-45046 | CRIT 9.0 | ransomware apache log4j It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default | 100.0% | |
| CVE-2017-6742 | HIGH 8.8 | cisco ios A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi | 21.4% | |
| CVE-2023-28252 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 49.0% | |
| CVE-2019-1388 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. | 8.6% | |
| CVE-2023-0266 | HIGH 7.9 | debian debian_linux A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. W | 3.7% | |
| CVE-2013-3163 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013 | 70.7% | |
| CVE-2023-24880 | MED 4.4 | ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 78.2% | |
| CVE-2023-23397 | CRIT 9.8 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 97.4% | |
| CVE-2022-41328 | MED 6.7 | fortinet fortios A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlyin | 12.3% | |
| CVE-2020-5741 | HIGH 7.2 | plex media_server Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | 72.9% | |
| CVE-2022-33891 | HIGH 8.8 | apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht | 93.1% | |
| CVE-2022-47986 | CRIT 9.8 | ransomware ibm aspera_faspex IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to ex | 100.0% | |
| CVE-2023-23376 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 10.9% | |
| CVE-2023-21823 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 5.6% | |
| CVE-2023-21715 | HIGH 7.3 | microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability | 12.0% | |
| CVE-2015-2291 | HIGH 7.8 | ransomware intel ethernet_diagnostics_driver_iqvw32.sys (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8 | 9.0% | |
| CVE-2023-21674 | HIGH 8.8 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 41.8% | |
| CVE-2022-41080 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 77.3% | |
| CVE-2022-44698 | MED 5.4 | ransomware microsoft windows_10_1607 Windows SmartScreen Security Feature Bypass Vulnerability | 76.3% | |
| CVE-2022-42475 | CRIT 9.8 | ransomware fortinet fortios A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote u | 99.5% | |
| CVE-2022-27518 | CRIT 9.8 | citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution | 6.9% | |
| CVE-2022-4135 | CRIT 9.6 | google chrome Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | 31.9% |