57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-37536 | HIGH 8.2 | apache xerces-c\+\+ An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. | 1.4% | — |
| CVE-2023-36038 | HIGH 8.2 | microsoft asp.net_core ASP.NET Core Denial of Service Vulnerability | 2.8% | — |
| CVE-2023-35335 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.8% | — |
| CVE-2023-33171 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-31027 | HIGH 8.2 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges. | 0.2% | — |
| CVE-2023-30428 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Broke | 0.8% | — |
| CVE-2023-28960 | HIGH 8.2 | juniper junos_os_evolved An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a local, authenticated low-privileged attacker to copy potentially malicious files into an existing Docker container on the local system. A follo | 0.2% | — |
| CVE-2023-28714 | HIGH 8.2 | intel proset\/wireless_wifi Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28385 | HIGH 8.2 | intel next_unit_of_computing_firmware Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access. | 0.2% | — |
| CVE-2023-24892 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | 3.5% | — |
| CVE-2023-23383 | HIGH 8.2 | microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability | 11.7% | — |
| CVE-2023-21806 | HIGH 8.2 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 0.8% | — |
| CVE-2023-2110 | HIGH 8.2 | obsidian obsidian Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens | 0.4% | — |
| CVE-2023-20869 | HIGH 8.2 | vmware fusion VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. | 2.0% | — |
| CVE-2023-2008 | HIGH 8.2 | linux linux_kernel A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escala | 1.0% | — |
| CVE-2023-20063 | HIGH 8.2 | cisco secure_firewall_management_center A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to e | 0.4% | — |
| CVE-2023-0975 | HIGH 8.2 | trellix agent A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. | 0.2% | — |
| CVE-2022-49279 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent integer overflow on 32 bit systems On a 32 bit system, the "len * sizeof(*p)" operation can have an integer overflow. | 0.6% | — |
| CVE-2022-46751 | HIGH 8.2 | apache ivy Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML file | 2.0% | — |
| CVE-2022-42476 | HIGH 8.2 | fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy version 7.2.0 through 7.2.2 and 7.0.0 through 7.0.8 allows privileged VDOM administrators to escalate their priv | 0.2% | — |
| CVE-2022-42291 | HIGH 8.2 | nvidia geforce_experience NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit cont | 0.2% | — |
| CVE-2022-36396 | HIGH 8.2 | intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2022-34321 | HIGH 8.2 | apache pulsar Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the | 1.8% | — |
| CVE-2022-31705 | HIGH 8.2 | vmware esxi VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's | 1.6% | — |
| CVE-2022-30196 | HIGH 8.2 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2.1% | — |