57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-53493 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: accel/qaic: tighten bounds checking in decode_message() Copy the bounds checking from encode_message() to decode_message(). This patch addresses the following concerns. Ensure that there i | 0.2% | — |
| CVE-2023-53194 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This adds a length check to guarantee the retrieved index root is legit. [ 162.459513] BUG: KASAN: use-after-free in hdr_find_e.isra.0+0x10c/0x3 | 0.2% | — |
| CVE-2023-52829 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps() reg_cap.phy_id is extracted from WMI event and could be an unexpected value in case some errors happen. As a re | 0.3% | — |
| CVE-2023-52629 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() | 0.2% | — |
| CVE-2023-47145 | HIGH 8.4 | ibm db2 IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402. | 0.2% | — |
| CVE-2023-44194 | HIGH 8.4 | juniper junos An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. The issue is caused by improper directory permissions on a certain system | 0.2% | — |
| CVE-2023-36569 | HIGH 8.4 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-3440 | HIGH 8.4 | hitachi jp1\/performance_management Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10- | 0.2% | — |
| CVE-2023-30431 | HIGH 8.4 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184. | 0.3% | — |
| CVE-2023-29360 | HIGH 8.4 | microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability | 22.1% | |
| CVE-2023-28956 | HIGH 8.4 | ibm spectrum_protect_backup-archive_client IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | 0.2% | — |
| CVE-2023-28291 | HIGH 8.4 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-27558 | HIGH 8.4 | ibm db2 IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executa | 0.2% | — |
| CVE-2023-25539 | HIGH 8.4 | dell networker Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying | 1.5% | — |
| CVE-2023-22875 | HIGH 8.4 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356. | 0.3% | — |
| CVE-2023-20854 | HIGH 8.4 | vmware workstation VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is inst | 0.3% | — |
| CVE-2023-0208 | HIGH 8.4 | nvidia data_center_gpu_manager NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow through the bound socket. A successful exploit of this vulnerability may lead to denial of service and data tampering. | 0.2% | — |
| CVE-2022-50442 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate buffer length while parsing index indx_read is called when we have some NTFS directory operations that need more information from the index buffers. This adds a sanity che | 0.2% | — |
| CVE-2022-49886 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Panic on bad configs that #VE on "private" memory access All normal kernel memory is "TDX private memory". This includes everything from kernel stacks to kernel text. Handling exc | 0.2% | — |
| CVE-2022-49451 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix list protocols enumeration in the base protocol While enumerating protocols implemented by the SCMI platform using BASE_DISCOVER_LIST_PROTOCOLS, the number of returne | 0.3% | — |
| CVE-2022-45048 | HIGH 8.4 | apache ranger Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | 1.1% | — |
| CVE-2022-43910 | HIGH 8.4 | ibm security_guardium IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. IBM X-Force ID: 240908. | 0.2% | — |
| CVE-2022-41736 | HIGH 8.4 | ibm spectrum_scale_container_native_storage_access IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that could allow a local user to obtain root privileges. IBM X-Force ID: 237810. | 0.2% | — |
| CVE-2022-39243 | HIGH 8.4 | nuprocess_project nuprocess NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perfor | 1.2% | — |
| CVE-2022-30222 | HIGH 8.4 | microsoft windows_10 Windows Shell Remote Code Execution Vulnerability | 0.7% | — |