57.469 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.469 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-25695 | MED 5.3 | apache airflow Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2. | 1.4% | — |
| CVE-2023-25514 | MED 5.3 | nvidia cuda_toolkit NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by tricking a user into running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limit | 0.2% | — |
| CVE-2023-25513 | MED 5.3 | nvidia cuda_toolkit NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by tricking a user into running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limit | 0.3% | — |
| CVE-2023-25512 | MED 5.3 | nvidia cuda_toolkit NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds memory read by running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of s | 0.3% | — |
| CVE-2023-24594 | MED 5.3 | f5 big-ip_access_policy_manager When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.6% | — |
| CVE-2023-22398 | MED 5.3 | juniper junos An Access of Uninitialized Pointer vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). When an MPLS ping is perform | 0.2% | — |
| CVE-2023-21743 | MED 5.3 | microsoft sharepoint_server Microsoft SharePoint Server Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2023-21720 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability | 1.2% | — |
| CVE-2023-21699 | MED 5.3 | microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-21682 | MED 5.3 | microsoft windows_10_1607 Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-21525 | MED 5.3 | microsoft windows_10_1607 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.5% | — |
| CVE-2023-20262 | MED 5.3 | cisco catalyst_sd-wan_manager A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to fu | 0.7% | — |
| CVE-2023-20255 | MED 5.3 | cisco meeting_server A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could e | 0.8% | — |
| CVE-2023-20232 | MED 5.3 | cisco unified_contact_center_express A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input val | 0.5% | — |
| CVE-2023-20088 | MED 5.3 | cisco finesse A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected thr | 0.8% | — |
| CVE-2023-20073 | MED 5.3 | cisco rv340_firmware A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insuffici | 90.1% | — |
| CVE-2023-20052 | MED 5.3 | cisco secure_endpoint On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote att | 7.0% | — |
| CVE-2023-20012 | MED 5.3 | cisco nexus_93180yc-fx3_firmware A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerabil | 0.3% | — |
| CVE-2023-1995 | MED 5.3 | hitachi hirdb_server Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, be | 0.5% | — |
| CVE-2023-1409 | MED 5.3 | mongodb mongodb If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in eff | 0.4% | — |
| CVE-2023-1048 | MED 5.3 | techpowerup dram_calculator_for_ryzen A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipulation leads to improper initialization. Local access is requir | 0.6% | — |
| CVE-2023-1004 | MED 5.3 | marktext marktext A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is required t | 0.4% | — |
| CVE-2023-1003 | MED 5.3 | typora typora A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit h | 0.4% | — |
| CVE-2023-0458 | MED 5.3 | debian debian_linux A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading | 0.7% | — |
| CVE-2022-48764 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2} Free the "struct kvm_cpuid_entry2" array on successful post-KVM_RUN KVM_SET_CPUID{,2} to fix a memory leak, the caller | 0.2% | — |