57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-42123 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free err_addr in some spec | 0.2% | — |
| CVE-2024-41817 | HIGH 7.0 | imagemagick imagemagick ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executin | 0.9% | — |
| CVE-2024-41022 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq() The "instance" variable needs to be signed for the error handling to work. | 0.2% | — |
| CVE-2024-39507 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may | 0.3% | — |
| CVE-2024-39492 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warning in mbox shutdown The return value of pm_runtime_get_sync() in cmdq_mbox_shutdown() will return 1 when pm runtime state is active, and we | 0.2% | — |
| CVE-2024-39425 | HIGH 7.0 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. Exploitation of this issue require local low-p | 0.2% | — |
| CVE-2024-39420 | HIGH 7.0 | adobe acrobat Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary co | 3.5% | — |
| CVE-2024-38612 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist | 0.7% | — |
| CVE-2024-38577 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow There is a possibility of buffer overflow in show_rcu_tasks_trace_gp_kthread() if counters, passed to sprintf() are huge. Count | 0.3% | — |
| CVE-2024-38576 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rcu: Fix buffer overflow in print_cpu_stall_info() The rcuc-starvation output from print_cpu_stall_info() might overflow the buffer if there is a huge difference in jiffies difference. The | 0.3% | — |
| CVE-2024-38561 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kunit: Fix kthread reference There is a race condition when a kthread finishes after the deadline and before the call to kthread_stop(), which may lead to use after free. | 0.2% | — |
| CVE-2024-38555 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Discard command completions in internal error Fix use after free when FW completion arrives while device is in internal error state. Avoid calling completion handler in this case, | 0.3% | — |
| CVE-2024-38248 | HIGH 7.0 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38246 | HIGH 7.0 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38201 | HIGH 7.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38158 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2024-38157 | HIGH 7.0 | microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2024-38137 | HIGH 7.0 | microsoft windows_10_21h2 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-38136 | HIGH 7.0 | microsoft windows_10_1809 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-38106 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 6.3% | |
| CVE-2024-38069 | HIGH 7.0 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0.3% | — |
| CVE-2024-38022 | HIGH 7.0 | microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-36899 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: Fix use after free in lineinfo_changed_notify The use-after-free issue occurs as follows: when the GPIO chip device file is being closed by invoking gpio_chrdev_release(), wat | 0.2% | — |
| CVE-2024-35986 | HIGH 7.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: phy: ti: tusb1210: Resolve charger-det crash if charger psy is unregistered The power_supply frame-work is not really designed for there to be long living in kernel references to power_suppl | 0.2% | — |
| CVE-2024-35898 | HIGH 7.0 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() nft_unregister_flowtable_type() within nf_flow_inet_module_exit() can concurrent with __nft_flowtable_type_get() w | 0.2% | — |