57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-37986 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37985 | MED 5.9 | microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-37984 | HIGH 8.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-37983 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37982 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37981 | HIGH 8.0 | microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-37980 | HIGH 8.8 | microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2024-37979 | MED 6.7 | microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-37978 | HIGH 8.0 | microsoft windows_11_22h2 Secure Boot Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-37977 | HIGH 8.0 | microsoft windows_11_21h2 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-37976 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37975 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-37974 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37973 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37972 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37971 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2024-37970 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-37969 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2024-37968 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.0% | — |
| CVE-2024-37966 | HIGH 7.1 | microsoft sql_server_2017 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-37965 | HIGH 8.8 | microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2024-37527 | MED 5.4 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure | 0.2% | — |
| CVE-2024-37391 | HIGH 7.8 | proton protonvpn ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | 0.3% | — |
| CVE-2024-37389 | MED 4.6 | apache nifi Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitra | 24.0% | — |
| CVE-2024-37385 | CRIT 9.8 | roundcube webmail Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. | 1.5% | — |