58.140 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.140 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-50024 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: Fix an unsafe loop on the list The kernel may crash when deleting a genetlink family if there are still listeners for that family: Oops: Kernel access of bad area, sig: 11 [#1] ... | 0.3% | — |
| CVE-2024-49860 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ACPI: sysfs: validate return type of _STR method Only buffer objects are valid return values of _STR. If something else is returned description_show() will access invalid memory. | 0.3% | — |
| CVE-2024-49107 | HIGH 7.3 | microsoft windows_10_1507 WmsRepair Service Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2024-49056 | HIGH 7.3 | microsoft airlift_microsoft_com Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2024-47669 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log writing function After commit a694291a6211 ("nilfs2: separate wait function from nilfs_segctor_write") was applied, the log writing function | 0.2% | — |
| CVE-2024-47667 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0) Errata #i2037 in AM65x/DRA80xM Processors Silicon Revision 1.0 (SPRZ452D_July 2018_Revised December 2019 [1]) mentions when an | 0.2% | — |
| CVE-2024-47561 | HIGH 7.3 | apache avro Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. | 3.3% | — |
| CVE-2024-46863 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, and we test !link->num_adr as a condition to end the loop in hda_sdw_machi | 0.2% | — |
| CVE-2024-46811 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk_tabl | 0.2% | — |
| CVE-2024-46764 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: add check for invalid name in btf_name_valid_section() If the length of the name string is 1 and the value of name[0] is NULL byte, an OOB vulnerability occurs in btf_name_valid_section | 0.2% | — |
| CVE-2024-46743 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells p | 0.3% | — |
| CVE-2024-45331 | HIGH 7.3 | fortinet fortianalyzer A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 | 0.2% | — |
| CVE-2024-44933 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl() A recent commit has modified the code in __bnxt_reserve_rings() to set the default RSS indirection table to default only when the | 0.2% | — |
| CVE-2024-43594 | HIGH 7.3 | microsoft system_center_2019 Microsoft System Center Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2024-43552 | HIGH 7.3 | microsoft windows_11_22h2 Windows Shell Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-43529 | HIGH 7.3 | microsoft windows_10_21h2 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-43495 | HIGH 7.3 | microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-43475 | HIGH 7.3 | microsoft windows_server_2008 Microsoft Windows Admin Center Information Disclosure Vulnerability | 1.8% | — |
| CVE-2024-43470 | HIGH 7.3 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-42093 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack is not recommended since it can cause potenti | 0.2% | — |
| CVE-2024-42088 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") removed the codec entry fo | 0.2% | — |
| CVE-2024-41767 | HIGH 7.3 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end databa | 0.3% | — |
| CVE-2024-41056 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files Use strnlen() instead of strlen() on the algorithm and coefficient name string arrays in V1 wmfw files. In V1 wmfw files the | 0.3% | — |
| CVE-2024-40971 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: remove clear SB_INLINECRYPT flag in default_options In f2fs_remount, SB_INLINECRYPT flag will be clear and re-set. If create new file or open file during this gap, these files will not | 0.3% | — |
| CVE-2024-40901 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when using test_bit() on a single word. The test_bit() and set_bit() functions | 0.3% | — |