IT
56.565 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.565 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2024-30051 HIGH 7.8 ransomware microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability 5.7%
CVE-2024-30040 HIGH 8.8 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 3.9%
CVE-2024-29988 HIGH 8.8 microsoft windows_10_1809 SmartScreen Prompt Security Feature Bypass Vulnerability 45.2%
CVE-2024-20359 MED 6.0 cisco adaptive_security_appliance_software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l 19.4%
CVE-2024-20353 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i 70.7%
CVE-2022-38028 HIGH 7.8 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 14.9%
CVE-2024-3400 CRIT 10.0 ransomware paloaltonetworks pan-os A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit 100.0%
CVE-2023-24955 HIGH 7.2 ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 85.4%
CVE-2023-48788 CRIT 9.8 ransomware fortinet forticlient_enterprise_management_server A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted pa 97.6%
CVE-2024-21338 HIGH 7.8 ransomware microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 59.8%
CVE-2023-29360 HIGH 8.4 microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability 22.1%
CVE-2024-21410 CRIT 9.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 12.7%
CVE-2020-3259 HIGH 7.5 ransomware cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could l 69.3%
CVE-2024-21412 HIGH 8.1 ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability 95.4%
CVE-2024-21351 HIGH 7.6 microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability 30.3%
CVE-2024-21762 CRIT 9.8 ransomware fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0 84.3%
CVE-2023-4762 HIGH 8.8 debian debian_linux Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 38.0%
CVE-2023-34048 CRIT 9.8 vmware vcenter_server vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. 99.4%
CVE-2023-6549 HIGH 8.2 citrix netscaler_application_delivery_controller Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read 57.6%
CVE-2023-6548 MED 5.5 citrix netscaler_application_delivery_controller Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf 3.2%
CVE-2023-29357 CRIT 9.8 ransomware microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 99.6%
CVE-2023-27524 HIGH 8.9 apache superset Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resourc 97.4%
CVE-2023-6345 CRIT 9.6 debian debian_linux Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) 19.5%
CVE-2023-36584 MED 5.4 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 3.1%
CVE-2023-36036 HIGH 7.8 microsoft windows_10_1507 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 16.7%