IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-38179 HIGH 8.8 microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability 0.4%
CVE-2024-38177 HIGH 7.8 microsoft app_installer Windows App Installer Spoofing Vulnerability 0.9%
CVE-2024-38176 HIGH 8.1 microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. 0.9%
CVE-2024-38175 CRIT 9.6 microsoft azure_managed_instance_for_apache_cassandra An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. 0.8%
CVE-2024-38173 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0.7%
CVE-2024-38172 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2024-38171 HIGH 7.8 microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability 0.9%
CVE-2024-38170 HIGH 7.1 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%
CVE-2024-38169 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.8%
CVE-2024-38168 HIGH 7.5 microsoft .net .NET and Visual Studio Denial of Service Vulnerability 2.7%
CVE-2024-38167 MED 6.5 microsoft .net .NET and Visual Studio Information Disclosure Vulnerability 1.4%
CVE-2024-38166 HIGH 8.2 microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. 0.8%
CVE-2024-38165 MED 6.5 microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability 1.3%
CVE-2024-38164 CRIT 9.6 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. 1.0%
CVE-2024-38163 HIGH 7.8 microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability 0.7%
CVE-2024-38162 HIGH 7.8 microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability 0.5%
CVE-2024-38161 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.8%
CVE-2024-38160 CRIT 9.1 microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability 2.2%
CVE-2024-38159 CRIT 9.1 microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability 2.2%
CVE-2024-38158 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.4%
CVE-2024-38157 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.5%
CVE-2024-38156 MED 6.1 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4%
CVE-2024-38155 MED 5.5 microsoft windows_10_1809 Security Center Broker Information Disclosure Vulnerability 0.7%
CVE-2024-38154 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.6%
CVE-2024-38153 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5%