57.065 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.065 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2024-35277 | HIGH 8.6 | fortinet fortimanager A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the | 0.7% | — |
| CVE-2024-35276 | MED 5.6 | fortinet fortianalyzer A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7 | 0.4% | — |
| CVE-2024-35275 | MED 6.6 | fortinet fortianalyzer A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http request | 0.8% | — |
| CVE-2024-35274 | LOW 2.3 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 | 0.2% | — |
| CVE-2024-35273 | HIGH 7.2 | fortinet fortianalyzer A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests. | 0.7% | — |
| CVE-2024-35272 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2024-35271 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2024-35270 | MED 5.3 | microsoft windows_10_1507 Windows iSCSI Service Denial of Service Vulnerability | 0.9% | — |
| CVE-2024-35267 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-35266 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-35265 | HIGH 7.0 | microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-35264 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2024-35263 | MED 5.7 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-35261 | HIGH 7.8 | microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-35260 | HIGH 8.0 | microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | 0.8% | — |
| CVE-2024-35256 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-35255 | MED 5.5 | microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35254 | HIGH 7.1 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35253 | MED 4.4 | microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-35252 | HIGH 7.5 | microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-35249 | HIGH 8.8 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | 3.4% | — |
| CVE-2024-35248 | HIGH 7.3 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-35247 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga region assumes that the low-level module registers a driver for the parent device and uses its own | 0.2% | — |
| CVE-2024-35201 | MED 6.7 | intel server_debug_and_provisioning_tool Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | 0.1% | — |
| CVE-2024-35200 | MED 5.3 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. | 0.9% | — |