IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-53214 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential memory corruption in __update_iostat_latency() Add iotype sanity check to avoid potential memory corruption. This is to fix the compile error below: fs/f2fs/ios 0.2% —
CVE-2023-52864 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: platform/x86: wmi: Fix opening of char device Since commit fa1f68db6ca7 ("drivers: misc: pass miscdevice pointer via file private data"), the miscdevice stores a pointer to itself inside fil 0.3% —
CVE-2023-52578 HIGH 7.0 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: use DEV_STATS_INC() syzbot/KCSAN reported data-races in br_handle_frame_finish() [1] This function can run from multiple cpus without mutual exclusion. Adopt SMP safe DEV_STATS 0.2% —
CVE-2023-51782 HIGH 7.0 debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition. 0.3% —
CVE-2023-51781 HIGH 7.0 debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition. 0.3% —
CVE-2023-51780 HIGH 7.0 debian debian_linux An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition. 0.5% —
CVE-2023-51043 HIGH 7.0 linux linux_kernel In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload. 0.2% —
CVE-2023-5097 HIGH 7.0 hypr workforce_access Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7. 0.2% —
CVE-2023-46813 HIGH 7.0 linux linux_kernel An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrar 0.7% —
CVE-2023-4611 HIGH 7.0 linux linux_kernel A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel informati 0.3% —
CVE-2023-4389 HIGH 7.0 linux linux_kernel A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked inter 0.3% —
CVE-2023-42753 HIGH 7.0 debian debian_linux An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer ou 0.5% —
CVE-2023-40596 HIGH 7.0 splunk splunk In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install m 0.2% —
CVE-2023-38176 HIGH 7.0 microsoft azure_arc-enabled_servers Azure Arc-Enabled Servers Elevation of Privilege Vulnerability 0.4% —
CVE-2023-38159 HIGH 7.0 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 5.6% —
CVE-2023-38155 HIGH 7.0 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.3% —
CVE-2023-38041 HIGH 7.0 ivanti secure_access_client A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. 0.7% —
CVE-2023-36902 HIGH 7.0 microsoft windows_10_1607 Windows Runtime Remote Code Execution Vulnerability 0.6% —
CVE-2023-36805 HIGH 7.0 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 1.8% —
CVE-2023-36776 HIGH 7.0 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 2.4% —
CVE-2023-36721 HIGH 7.0 microsoft windows_10_1809 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.4% —
CVE-2023-36568 HIGH 7.0 microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 0.4% —
CVE-2023-36565 HIGH 7.0 microsoft 365_copilot Microsoft Office Graphics Elevation of Privilege Vulnerability 0.4% —
CVE-2023-36427 HIGH 7.0 microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability 1.5% —
CVE-2023-36405 HIGH 7.0 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.4% —