58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2023-25195 | HIGH 8.1 | apache fineract Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic. This issue affects Apache Fineract: fr | 1.0% | — |
| CVE-2023-25194 | HIGH 8.8 | apache kafka_connect A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security proto | 95.8% | — |
| CVE-2023-25148 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note: an attac | 0.4% | — |
| CVE-2023-25147 | MED 6.7 | trendmicro apex_one An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must | 0.2% | — |
| CVE-2023-25146 | HIGH 7.8 | trendmicro apex_one A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped | 0.4% | — |
| CVE-2023-25145 | HIGH 7.8 | trendmicro apex_one A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the | 0.4% | — |
| CVE-2023-25144 | HIGH 7.8 | trendmicro apex_one An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership. | 0.3% | — |
| CVE-2023-25143 | CRIT 9.8 | trendmicro apex_one An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | 1.7% | — |
| CVE-2023-25141 | HIGH 7.5 | apache sling_jcr_base Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access | 1.2% | — |
| CVE-2023-2513 | MED 6.7 | linux linux_kernel A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors. | 0.2% | — |
| CVE-2023-25071 | MED 5.6 | intel arc_a_graphics NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access. | 0.2% | — |
| CVE-2023-25069 | HIGH 8.8 | trendmicro txone_stellarone TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker | 1.0% | — |
| CVE-2023-25012 | MED 4.6 | linux linux_kernel The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long. | 0.8% | — |
| CVE-2023-24998 | HIGH 7.5 | apache commons_fileupload Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the | 48.8% | — |
| CVE-2023-24997 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inl | 1.4% | — |
| CVE-2023-24977 | HIGH 7.5 | apache inlong Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 h | 1.2% | — |
| CVE-2023-24965 | MED 5.8 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713. | 0.5% | — |
| CVE-2023-24964 | MED 6.2 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. | 0.1% | — |
| CVE-2023-24960 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 24 | 1.4% | — |
| CVE-2023-24954 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability | 1.8% | — |
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24950 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 67.5% | — |
| CVE-2023-24949 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 24.6% | — |
| CVE-2023-24948 | HIGH 7.4 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-24947 | HIGH 8.8 | microsoft windows_10_1607 Windows Bluetooth Driver Remote Code Execution Vulnerability | 0.7% | — |