57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-38179 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-38177 | HIGH 7.8 | microsoft app_installer Windows App Installer Spoofing Vulnerability | 0.9% | — |
| CVE-2024-38176 | HIGH 8.1 | microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38175 | CRIT 9.6 | microsoft azure_managed_instance_for_apache_cassandra An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-38173 | MED 6.7 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38172 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38171 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38170 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38169 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38168 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.7% | — |
| CVE-2024-38167 | MED 6.5 | microsoft .net .NET and Visual Studio Information Disclosure Vulnerability | 1.4% | — |
| CVE-2024-38166 | HIGH 8.2 | microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. | 0.8% | — |
| CVE-2024-38165 | MED 6.5 | microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability | 1.3% | — |
| CVE-2024-38164 | CRIT 9.6 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | 1.0% | — |
| CVE-2024-38163 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38162 | HIGH 7.8 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-38161 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38160 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-38159 | CRIT 9.1 | microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-38158 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2024-38157 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2024-38156 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.4% | — |
| CVE-2024-38155 | MED 5.5 | microsoft windows_10_1809 Security Center Broker Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-38154 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-38153 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |