58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35342 | HIGH 7.8 | microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35340 | HIGH 7.8 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2023-35337 | HIGH 7.8 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35328 | HIGH 7.8 | microsoft windows_10_1507 Windows Transaction Manager Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35323 | HIGH 7.8 | microsoft windows_11_21h2 Windows OLE Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35320 | HIGH 7.8 | microsoft windows_10_1607 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35317 | HIGH 7.8 | microsoft windows_server_2012 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2023-35313 | HIGH 7.8 | microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35312 | HIGH 7.8 | microsoft windows_10_1507 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35305 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35304 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35299 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35080 | HIGH 7.8 | ivanti secure_access_client A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, den | 0.7% | — |
| CVE-2023-35001 | HIGH 7.8 | debian debian_linux Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace | 1.5% | — |
| CVE-2023-34395 | HIGH 7.8 | apache apache-airflow-providers-odbc Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver pa | 0.8% | — |
| CVE-2023-34319 | HIGH 7.8 | debian debian_linux The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the logic introduced there didn't account for the extreme case of the entire | 0.3% | — |
| CVE-2023-34148 | HIGH 7.8 | trendmicro apex_one An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. | 0.2% | — |
| CVE-2023-34147 | HIGH 7.8 | trendmicro apex_one An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. | 0.2% | — |
| CVE-2023-34146 | HIGH 7.8 | trendmicro apex_one An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. | 0.2% | — |
| CVE-2023-34145 | HIGH 7.8 | trendmicro apex_one An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execut | 0.3% | — |
| CVE-2023-34144 | HIGH 7.8 | trendmicro apex_one An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execut | 0.3% | — |
| CVE-2023-34057 | HIGH 7.8 | vmware tools VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate privileges within the virtual machine. | 0.2% | — |
| CVE-2023-34052 | HIGH 7.8 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass. | 0.2% | — |
| CVE-2023-3390 | HIGH 7.8 | linux linux_kernel A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vu | 0.9% | — |
| CVE-2023-3389 | HIGH 7.8 | canonical ubuntu_linux A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac | 0.7% | — |