58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28218 | HIGH 7.0 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 12.3% | — |
| CVE-2023-28216 | HIGH 7.0 | microsoft windows_10_1507 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-27470 | HIGH 7.0 | n-able take_control BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion. | 0.5% | — |
| CVE-2023-25839 | HIGH 7.0 | esri arcgis_insights There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted i | 0.2% | — |
| CVE-2023-24914 | HIGH 7.0 | microsoft windows_11_22h2 Win32k Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-24899 | HIGH 7.0 | microsoft windows_11_21h2 Windows Graphics Component Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-24861 | HIGH 7.0 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-23393 | HIGH 7.0 | microsoft windows_10_1809 Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability | 0.2% | — |
| CVE-2023-23385 | HIGH 7.0 | microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-2270 | HIGH 7.0 | netskope netskope The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope client before R100 in this service utilized a relative path to | 0.3% | — |
| CVE-2023-22657 | HIGH 7.0 | f5 f5os-a On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not e | 0.4% | — |
| CVE-2023-22636 | HIGH 7.0 | fortinet fortiweb An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request. | 0.2% | — |
| CVE-2023-21771 | HIGH 7.0 | microsoft windows_10 Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-21739 | HIGH 7.0 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21733 | HIGH 7.0 | microsoft windows_10_20h2 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-21542 | HIGH 7.0 | microsoft windows_10_1607 Windows Installer Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-21532 | HIGH 7.0 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-21531 | HIGH 7.0 | microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-2006 | HIGH 7.0 | linux linux_kernel A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and e | 0.4% | — |
| CVE-2023-1989 | HIGH 7.0 | debian debian_linux A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices. | 0.4% | — |
| CVE-2023-1476 | HIGH 7.0 | linux linux_kernel A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privile | 0.2% | — |
| CVE-2023-1077 | HIGH 7.0 | debian debian_linux In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which woul | 0.3% | — |
| CVE-2022-50129 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix a use-after-free Change the LIO port members inside struct srpt_port from regular members into pointers. Allocate the LIO port data structures from inside srpt_make_tport() an | 0.2% | — |
| CVE-2022-50082 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ext4: fix warning in ext4_iomap_begin as race between bmap and write We got issue as follows: ------------[ cut here ]------------ WARNING: CPU: 3 PID: 9310 at fs/ext4/inode.c:3441 ext4_ioma | 0.2% | — |
| CVE-2022-50079 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check correct bounds for stream encoder instances for DCN303 [Why & How] eng_id for DCN303 cannot be more than 1, since we have only two instances of stream encoders. Check | 0.3% | — |