58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-53214 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential memory corruption in __update_iostat_latency() Add iotype sanity check to avoid potential memory corruption. This is to fix the compile error below: fs/f2fs/ios | 0.2% | — |
| CVE-2023-52864 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via file private data"), the miscdevice stores a pointer to itself inside fil | 0.3% | — |
| CVE-2023-52578 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: use DEV_STATS_INC() syzbot/KCSAN reported data-races in br_handle_frame_finish() [1] This function can run from multiple cpus without mutual exclusion. Adopt SMP safe DEV_STATS | 0.2% | — |
| CVE-2023-51782 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition. | 0.3% | — |
| CVE-2023-51781 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition. | 0.3% | — |
| CVE-2023-51780 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition. | 0.5% | — |
| CVE-2023-51043 | HIGH 7.0 | linux linux_kernel In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload. | 0.2% | — |
| CVE-2023-5097 | HIGH 7.0 | hypr workforce_access Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7. | 0.2% | — |
| CVE-2023-46813 | HIGH 7.0 | linux linux_kernel An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrar | 0.7% | — |
| CVE-2023-4611 | HIGH 7.0 | linux linux_kernel A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel informati | 0.3% | — |
| CVE-2023-4389 | HIGH 7.0 | linux linux_kernel A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked inter | 0.3% | — |
| CVE-2023-42753 | HIGH 7.0 | debian debian_linux An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer ou | 0.5% | — |
| CVE-2023-40596 | HIGH 7.0 | splunk splunk In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install m | 0.2% | — |
| CVE-2023-38176 | HIGH 7.0 | microsoft azure_arc-enabled_servers Azure Arc-Enabled Servers Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-38159 | HIGH 7.0 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 5.6% | — |
| CVE-2023-38155 | HIGH 7.0 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-38041 | HIGH 7.0 | ivanti secure_access_client A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | 0.7% | — |
| CVE-2023-36902 | HIGH 7.0 | microsoft windows_10_1607 Windows Runtime Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-36805 | HIGH 7.0 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 1.8% | — |
| CVE-2023-36776 | HIGH 7.0 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2023-36721 | HIGH 7.0 | microsoft windows_10_1809 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-36568 | HIGH 7.0 | microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-36565 | HIGH 7.0 | microsoft 365_copilot Microsoft Office Graphics Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-36427 | HIGH 7.0 | microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-36405 | HIGH 7.0 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |