IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-38230 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a 2.7% —
CVE-2023-38217 MED 5.5 adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploit 0.4% —
CVE-2023-38216 MED 5.5 adobe bridge Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation 0.4% —
CVE-2023-38213 MED 5.5 adobe dimension Adobe Dimension version 3.4.9 is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user inter 0.3% —
CVE-2023-38160 MED 5.5 microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability 0.9% —
CVE-2023-38140 MED 5.5 microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability 1.1% —
CVE-2023-38046 MED 5.5 paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. 0.5% —
CVE-2023-3773 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, lead 0.3% —
CVE-2023-3772 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel c 0.5% —
CVE-2023-37454 MED 5.5 linux linux_kernel An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective abou 0.4% —
CVE-2023-37143 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). 0.8% —
CVE-2023-37142 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). 0.8% —
CVE-2023-37141 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). 0.8% —
CVE-2023-37140 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). 0.8% —
CVE-2023-37139 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). 0.9% —
CVE-2023-36914 MED 5.5 microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability 0.6% —
CVE-2023-36907 MED 5.5 microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability 1.7% —
CVE-2023-36906 MED 5.5 microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability 2.0% —
CVE-2023-36905 MED 5.5 microsoft windows_10 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability 1.7% —
CVE-2023-36889 MED 5.5 microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability 0.6% —
CVE-2023-36872 MED 5.5 microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability 0.8% —
CVE-2023-36840 MED 5.5 juniper junos A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved, when a specific L2 0.2% —
CVE-2023-36838 MED 5.5 juniper junos An Out-of-bounds Read vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a local, authenticated attacker with low privileges, to cause a Denial of Service (DoS). If a low privileged user executes a specific C 0.2% —
CVE-2023-36803 MED 5.5 microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability 1.0% —
CVE-2023-36728 MED 5.5 microsoft odbc_driver_for_sql_server Microsoft SQL Server Denial of Service Vulnerability 0.9% —