IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.569 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-4577 CRIT 9.8 ransomware fedoraproject fedora In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 100.0%
CVE-2024-26169 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 4.0%
CVE-2022-2586 MED 5.3 canonical ubuntu_linux It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted. 10.5%
CVE-2024-20399 MED 6.0 cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu 4.3%
CVE-2024-38112 HIGH 7.5 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 84.2%
CVE-2024-38080 HIGH 7.8 microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability 7.1%
CVE-2022-22948 MED 6.5 vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. 13.3%
CVE-2012-4792 HIGH 8.8 microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnB 78.8%
CVE-2024-37085 MED 6.8 ransomware vmware cloud_foundation VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere 26.0%
CVE-2018-0824 HIGH 8.8 microsoft windows_10_1507 A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1 72.4%
CVE-2024-36971 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first 2.7%
CVE-2024-32113 CRIT 9.8 apache ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. 99.4%
CVE-2024-38213 MED 6.5 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 13.6%
CVE-2024-38193 HIGH 7.8 microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 27.4%
CVE-2024-38189 HIGH 8.8 microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability 8.2%
CVE-2024-38178 HIGH 7.5 microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability 41.4%
CVE-2024-38107 HIGH 7.8 microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability 1.6%
CVE-2024-38106 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 6.3%
CVE-2022-0185 HIGH 8.4 linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw 25.2%
CVE-2021-31196 HIGH 7.2 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 54.1%
CVE-2024-7971 CRIT 9.6 google chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 20.7%
CVE-2024-38856 CRIT 9.8 apache ofbiz Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code o 99.4%
CVE-2024-7965 HIGH 8.8 google chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 18.5%
CVE-2024-7262 HIGH 7.8 kingsoft wps_office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click 1.8%
CVE-2017-1000253 HIGH 7.8 ransomware centos centos Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371 10.7%