IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-7979 HIGH 7.8 google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium) 0.2%
CVE-2024-7977 HIGH 7.8 google chrome Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium) 0.3%
CVE-2024-7890 HIGH 7.3 citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows 0.2%
CVE-2024-7889 HIGH 7.3 citrix workspace Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows 0.2%
CVE-2024-7634 MED 4.9 f5 nginx_agent NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. 0.5%
CVE-2024-7577 MED 4.4 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product. 0.3%
CVE-2024-7571 HIGH 7.8 ivanti secure_access_client Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. 0.3%
CVE-2024-7553 HIGH 7.3 mongodb c_driver Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted 0.3%
CVE-2024-7347 MED 4.7 f5 nginx_open_source NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with 0.3%
CVE-2024-7263 HIGH 7.8 kingsoft wps_office Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitigate C 0.4%
CVE-2024-7125 HIGH 7.8 hitachi ops_center_common_services Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01. 0.2%
CVE-2024-7023 HIGH 8.8 google chrome Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium) 0.4%
CVE-2024-7021 MED 4.3 google chrome Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) 0.2%
CVE-2024-7017 HIGH 7.5 google chrome Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 0.2%
CVE-2024-6972 MED 6.5 octopus octopus_server In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. 0.2%
CVE-2024-6913 HIGH 8.8 perkinelmer processplus Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0. 1.4%
CVE-2024-6912 CRIT 9.8 perkinelmer processplus Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. 1.1%
CVE-2024-6746 MED 4.3 easyspider easyspider A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js of the component HTTP GET Request Handler. The manipulation 3.3%
CVE-2024-6714 HIGH 8.8 canonical ubuntu_desktop_provision An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. 0.3%
CVE-2024-6677 HIGH 7.8 citrix uberagent Privilege escalation in uberAgent 0.2%
CVE-2024-6293 HIGH 8.8 fedoraproject fedora Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.6%
CVE-2024-6292 HIGH 8.8 fedoraproject fedora Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 0.6%
CVE-2024-6286 HIGH 7.8 citrix workspace Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows 0.4%
CVE-2024-6236 HIGH 7.5 citrix netscaler_agent Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX 0.7%
CVE-2024-6235 HIGH 8.8 citrix netscaler_console Sensitive information disclosure in NetScaler Console 21.2%