58.140 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.140 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-39563 | HIGH 7.3 | juniper junos_space A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the | 1.3% | — |
| CVE-2024-39546 | HIGH 7.3 | juniper junos_os_evolved A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute | 0.2% | — |
| CVE-2024-39472 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by mkfs") added a fixup for incorrect h_size values us | 0.3% | — |
| CVE-2024-38659 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: enic: Validate length of nl attributes in enic_set_vf_port enic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE is of length PORT_PROFILE_MAX and that the nl attributes IFLA_PORT | 0.2% | — |
| CVE-2024-38611 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: i2c: et8ek8: Don't strip remove function when driver is builtin Using __exit for the remove function results in the remove callback being discarded with CONFIG_VIDEO_ET8EK8=y. When su | 0.2% | — |
| CVE-2024-38552 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of bounds issue in the color transformation function. The issue could occur when the index | 0.3% | — |
| CVE-2024-38538 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's xmit path by sending a short (less than ETH_HLEN bytes) skb. T | 0.3% | — |
| CVE-2024-38226 | HIGH 7.3 | microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2.7% | |
| CVE-2024-38202 | HIGH 7.3 | microsoft windows_10_1607 Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization | 1.7% | — |
| CVE-2024-38081 | HIGH 7.3 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-38033 | HIGH 7.3 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-36943 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix loss of young/dirty bits during pagemap scan make_uffd_wp_pte() was previously doing: pte = ptep_get(ptep); ptep_modify_prot_start(ptep); pte = pte_mkuffd_wp(pte | 0.2% | — |
| CVE-2024-36507 | HIGH 7.3 | fortinet forticlient A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering. | 0.3% | — |
| CVE-2024-36448 | HIGH 7.3 | apache iotdb_workbench ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users a | 0.7% | — |
| CVE-2024-35899 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: flush pending destroy work before exit_net release Similar to 2c9f0293280e ("netfilter: nf_tables: flush pending destroy work before netlink notifier") to address a rac | 0.2% | — |
| CVE-2024-35888 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: erspan: make sure erspan_base_hdr is present in skb->head syzbot reported a problem in ip6erspan_rcv() [1] Issue is that ip6erspan_rcv() (and erspan_rcv()) no longer make sure erspan_base_h | 0.6% | — |
| CVE-2024-35248 | HIGH 7.3 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-33508 | HIGH 7.3 | fortinet forticlient_enterprise_management_server An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations | 1.3% | — |
| CVE-2024-30102 | HIGH 7.3 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-30093 | HIGH 7.3 | microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-30061 | HIGH 7.3 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1.4% | — |
| CVE-2024-29131 | HIGH 7.3 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 2.1% | — |
| CVE-2024-29063 | HIGH 7.3 | microsoft azure_ai_search Azure AI Search Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-29007 | HIGH 7.3 | apache cloudstack The CloudStack management server and secondary storage VM could be tricked into making requests to restricted or random resources by means of following 301 HTTP redirects presented by external servers when downloading templates or ISOs. Users are recommended t | 0.8% | — |
| CVE-2024-27303 | HIGH 7.3 | electron electron-builder electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open | 0.3% | — |