57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.298 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2024-26587 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PHC gets initialized in nsim_init_netdevsim(), which is only called if (nsim_dev_port_is_pf()). Create a counterpart of nsim_init_netdevsim() | 0.2% | — |
| CVE-2024-26586 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a li | 0.2% | — |
| CVE-2024-26585 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). | 0.6% | — |
| CVE-2024-26584 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY in | 0.7% | — |
| CVE-2024-26583 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past th | 0.5% | — |
| CVE-2024-26582 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, an | 0.7% | — |
| CVE-2024-26581 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval e | 2.2% | — |
| CVE-2024-26580 | CRIT 9.1 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or | 1.2% | — |
| CVE-2024-26579 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2 | 1.1% | — |
| CVE-2024-26578 | MED 5.9 | apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. | 0.9% | — |
| CVE-2024-26362 | HIGH 8.8 | enpass password_manager HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note. | 0.6% | — |
| CVE-2024-26308 | MED 5.5 | apache commons_compress Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue. | 0.9% | — |
| CVE-2024-26307 | MED 5.3 | apache doris Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal | 0.2% | — |
| CVE-2024-26280 | MED 4.7 | apache airflow Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names and usernames they were not permitted to view. With 2.8.2 and newer, Ops and Viewer users do n | 1.9% | — |
| CVE-2024-26257 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-26256 | HIGH 7.8 | fedoraproject fedora Libarchive Remote Code Execution Vulnerability | 84.8% | — |
| CVE-2024-26255 | MED 5.5 | microsoft windows_10_1809 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26254 | HIGH 7.5 | microsoft windows_10_1809 Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability | 3.1% | — |
| CVE-2024-26253 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26252 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26251 | MED 6.8 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2024-26250 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-26248 | HIGH 7.5 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-26247 | MED 4.7 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-26246 | LOW 3.9 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |