57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-20670 | HIGH 8.1 | microsoft outlook Outlook for Windows Spoofing Vulnerability | 2.3% | — |
| CVE-2024-20669 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-20667 | HIGH 7.5 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-20666 | MED 6.6 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 3.1% | — |
| CVE-2024-20665 | MED 6.1 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-20664 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.0% | — |
| CVE-2024-20663 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 1.9% | — |
| CVE-2024-20662 | MED 4.9 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | 1.9% | — |
| CVE-2024-20661 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.8% | — |
| CVE-2024-20660 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.0% | — |
| CVE-2024-20659 | HIGH 7.1 | microsoft windows_10_1809 Windows Hyper-V Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-20658 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-20657 | HIGH 7.0 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-20656 | HIGH 7.8 | microsoft visual_studio Visual Studio Elevation of Privilege Vulnerability | 3.9% | — |
| CVE-2024-20655 | MED 6.6 | microsoft windows_server_2008 Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-20654 | HIGH 8.0 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-20653 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Common Log File System Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2024-20652 | HIGH 8.1 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2024-20540 | MED 5.4 | cisco unified_contact_center_management_portal A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the | 0.3% | — |
| CVE-2024-20539 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not su | 0.3% | — |
| CVE-2024-20538 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not suffic | 0.3% | — |
| CVE-2024-20537 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of A | 0.5% | — |
| CVE-2024-20536 | HIGH 8.8 | cisco nexus_dashboard_fabric_controller A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This | 0.8% | — |
| CVE-2024-20534 | MED 4.8 | cisco desk_phone_9841_with_multiplatform_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) a | 0.3% | — |
| CVE-2024-20533 | MED 4.8 | cisco desk_phone_9841_with_multiplatform_firmware A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) a | 0.3% | — |