57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26982 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Squashfs: check the inode number is not the invalid value of zero Syskiller has produced an out of bounds access in fill_meta_index(). That out of bounds access is ultimately caused because | 0.3% | — |
| CVE-2024-26791 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: dev-replace: properly validate device names There's a syzbot report that device name buffers passed to device replace are not properly checked for string termination which could lead | 0.2% | — |
| CVE-2024-26763 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. | 0.3% | — |
| CVE-2024-26674 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups During memory error injection test on kernels >= v6.4, the kernel panics like below. However, this issue couldn't be reproduc | 0.3% | — |
| CVE-2024-26673 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - Disallow families other than NFPROTO_{IPV4,IPV6,INET}. - Disallow layer 4 protocol with no ports, since des | 0.2% | — |
| CVE-2024-26672 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()' Fixes the below: drivers/gpu/drm/amd/amdgpu/amdgpu_mca.c:377 amdgpu_mca_smu_get_mca_e | 0.2% | — |
| CVE-2024-26669 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When a qdisc is deleted from a net device the stack instructs the underlying driver to remove its flow offload callback from the associated filt | 0.2% | — |
| CVE-2024-26666 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix RCU use in TDLS fast-xmit This looks up the link under RCU protection, but isn't guaranteed to actually have protection. Fix that. | 0.3% | — |
| CVE-2024-26630 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache walk In cachestat, we access the folio from the page cache's xarray to compute its page offset, and check for its dirty and writeback flags. | 0.3% | — |
| CVE-2024-26593 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions According to the Intel datasheets, software must reset the block buffer index twice for block process call transactions: once before writing th | 0.3% | — |
| CVE-2024-23306 | HIGH 7.1 | f5 big-ip_next_cloud-native_network_functions A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.2% | — |
| CVE-2024-22270 | HIGH 7.1 | vmware fusion VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained | 0.5% | — |
| CVE-2024-22269 | HIGH 7.1 | vmware fusion VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a | 0.5% | — |
| CVE-2024-22268 | HIGH 7.1 | vmware fusion VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial | 0.5% | — |
| CVE-2024-22255 | HIGH 7.1 | vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | 2.3% | — |
| CVE-2024-21643 | HIGH 7.1 | microsoft identitymodel_extensions IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Mi | 2.2% | — |
| CVE-2024-21402 | HIGH 7.1 | microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-21390 | HIGH 7.1 | microsoft authenticator Microsoft Authenticator Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-20689 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-20688 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-20659 | HIGH 7.1 | microsoft windows_10_1809 Windows Hyper-V Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-20421 | HIGH 7.1 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected d | 0.2% | — |
| CVE-2024-0206 | HIGH 7.1 | trellix anti-malware_engine A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trel | 0.2% | — |
| CVE-2023-6610 | HIGH 7.1 | linux linux_kernel An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. | 0.4% | — |
| CVE-2023-6606 | HIGH 7.1 | linux linux_kernel An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. | 0.5% | — |