IT
57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.057 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-20670 HIGH 8.1 microsoft outlook Outlook for Windows Spoofing Vulnerability 2.3%
CVE-2024-20669 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2024-20667 HIGH 7.5 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.4%
CVE-2024-20666 MED 6.6 microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability 3.1%
CVE-2024-20665 MED 6.1 microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability 0.7%
CVE-2024-20664 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 2.0%
CVE-2024-20663 MED 6.5 microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure 1.9%
CVE-2024-20662 MED 4.9 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability 1.9%
CVE-2024-20661 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.8%
CVE-2024-20660 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 2.0%
CVE-2024-20659 HIGH 7.1 microsoft windows_10_1809 Windows Hyper-V Security Feature Bypass Vulnerability 0.9%
CVE-2024-20658 HIGH 7.8 microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability 0.7%
CVE-2024-20657 HIGH 7.0 microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability 0.6%
CVE-2024-20656 HIGH 7.8 microsoft visual_studio Visual Studio Elevation of Privilege Vulnerability 3.9%
CVE-2024-20655 MED 6.6 microsoft windows_server_2008 Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability 1.4%
CVE-2024-20654 HIGH 8.0 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2024-20653 HIGH 7.8 microsoft windows_10_1507 Microsoft Common Log File System Elevation of Privilege Vulnerability 4.5%
CVE-2024-20652 HIGH 8.1 microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability 2.1%
CVE-2024-20540 MED 5.4 cisco unified_contact_center_management_portal A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the 0.3%
CVE-2024-20539 MED 4.8 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not su 0.3%
CVE-2024-20538 MED 6.1 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not suffic 0.3%
CVE-2024-20537 MED 6.5 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of A 0.5%
CVE-2024-20536 HIGH 8.8 cisco nexus_dashboard_fabric_controller A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This 0.8%
CVE-2024-20534 MED 4.8 cisco desk_phone_9841_with_multiplatform_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) a 0.3%
CVE-2024-20533 MED 4.8 cisco desk_phone_9841_with_multiplatform_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) a 0.3%