58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36642 | MED 6.7 | fortinet fortitester An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments t | 0.2% | — |
| CVE-2023-36640 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all vers | 0.3% | — |
| CVE-2023-36003 | MED 6.7 | microsoft windows_10_1507 XAML Diagnostics Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2023-35012 | MED 6.7 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with SYSADM privileges could overflow the buffer and execute | 0.2% | — |
| CVE-2023-34046 | MED 6.7 | vmware fusion VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrad | 0.1% | — |
| CVE-2023-34043 | MED 6.7 | vmware aria_operations VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | 0.2% | — |
| CVE-2023-33952 | MED 6.7 | linux linux_kernel A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which ma | 0.5% | — |
| CVE-2023-33951 | MED 6.7 | linux linux_kernel A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to | 0.3% | — |
| CVE-2023-32479 | MED 6.7 | dell encryption Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could poten | 0.1% | — |
| CVE-2023-32269 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However, in order for an attacker to exploit this, the system must hav | 0.3% | — |
| CVE-2023-32055 | MED 6.7 | microsoft windows_10_1507 Active Template Library Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-3159 | MED 6.7 | linux linux_kernel A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails. | 0.2% | — |
| CVE-2023-29177 | MED 6.7 | fortinet fortiadc Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands | 0.2% | — |
| CVE-2023-29165 | MED 6.7 | intel arc_a_graphics Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28772 | MED 6.7 | linux linux_kernel An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow. | 0.7% | — |
| CVE-2023-28740 | MED 6.7 | intel quickassist_technology Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28378 | MED 6.7 | intel quickassist_technology_firmware Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28065 | MED 6.7 | dell alienware_update Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalatio | 0.2% | — |
| CVE-2023-28000 | MED 6.7 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized | 0.2% | — |
| CVE-2023-27382 | MED 6.7 | intel nuc_p14e_laptop_element Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.1% | — |
| CVE-2023-27305 | MED 6.7 | intel arc_a_graphics Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-26203 | MED 6.7 | fortinet fortinac A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shel | 0.2% | — |
| CVE-2023-25147 | MED 6.7 | trendmicro apex_one An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must | 0.2% | — |
| CVE-2023-2513 | MED 6.7 | linux linux_kernel A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors. | 0.2% | — |
| CVE-2023-24932 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 10.6% | — |