57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-24779 | MED 5.0 | apache superset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to una | 0.7% | — |
| CVE-2024-24778 | MED 6.5 | apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe | 0.7% | — |
| CVE-2024-24775 | HIGH 7.5 | f5 big-ip_access_policy_manager When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-24773 | MED 4.9 | apache superset Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which | 0.8% | — |
| CVE-2024-24772 | MED 4.3 | apache superset A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to | 1.0% | — |
| CVE-2024-24749 | HIGH 7.5 | geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi | 0.8% | — |
| CVE-2024-24746 | HIGH 7.5 | apache nimble Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: throu | 1.4% | — |
| CVE-2024-24683 | MED 6.5 | apache hop_engine Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet pag | 1.2% | — |
| CVE-2024-24576 | CRIT 10.0 | fedoraproject fedora Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. | 20.3% | — |
| CVE-2024-24549 | HIGH 7.5 | apache tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after a | 23.1% | — |
| CVE-2024-24482 | CRIT 9.8 | apktool apktool Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. | 1.2% | — |
| CVE-2024-2433 | MED 4.3 | paloaltonetworks pan-os An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th | 0.6% | — |
| CVE-2024-2432 | MED 4.5 | paloaltonetworks globalprotect A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race c | 0.4% | — |
| CVE-2024-2431 | MED 5.5 | paloaltonetworks globalprotect An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode. | 0.2% | — |
| CVE-2024-24278 | HIGH 7.5 | teamwire teamwire An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function. | 0.7% | — |
| CVE-2024-24275 | CRIT 9.6 | teamwire teamwire Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. | 0.9% | — |
| CVE-2024-23982 | HIGH 7.5 | f5 big-ip_policy_enforcement_manager When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and | 0.5% | — |
| CVE-2024-23979 | HIGH 7.5 | f5 big-ip_access_policy_manager When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which ha | 0.3% | — |
| CVE-2024-23976 | MED 6.0 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (Eo | 0.2% | — |
| CVE-2024-23953 | MED 6.5 | apache hive Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are r | 1.2% | — |
| CVE-2024-23952 | MED 6.5 | apache superset This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This | 1.7% | — |
| CVE-2024-23946 | MED 5.3 | apache ofbiz Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. | 3.1% | — |
| CVE-2024-23945 | MED 5.9 | apache hive Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities a | 1.5% | — |
| CVE-2024-23944 | MED 5.3 | apache zookeeper Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKee | 0.2% | — |
| CVE-2024-23940 | HIGH 7.8 | trendmicro air_support Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library | 0.6% | — |