IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-43610 HIGH 7.4 microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector 1.1%
CVE-2024-43553 HIGH 7.4 microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2024-43550 HIGH 7.4 microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability 1.1%
CVE-2024-3383 HIGH 7.4 paloaltonetworks pan-os A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed 0.6%
CVE-2024-33507 HIGH 7.4 fortinet fortiisolator An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauth 0.4%
CVE-2024-32049 HIGH 7.4 f5 big-ip_next_central_manager BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5%
CVE-2024-28883 HIGH 7.4 f5 big-ip_access_policy_manager An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support ( 0.2%
CVE-2024-27309 HIGH 7.4 apache kafka While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated wit 1.1%
CVE-2024-26194 HIGH 7.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.4%
CVE-2024-22234 HIGH 7.4 vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl 0.7%
CVE-2024-21589 HIGH 7.4 juniper paragon_active_assurance_control_center An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configuration information. A 0.4%
CVE-2024-20406 HIGH 7.4 cisco ios_xr A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. 0.2%
CVE-2024-20327 HIGH 7.4 cisco ios_xr A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service 0.3%
CVE-2024-20317 HIGH 7.4 cisco ios_xr A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dropped, resulting in a 0.2%
CVE-2024-20313 HIGH 7.4 cisco ios_xe A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to 0.3%
CVE-2024-20312 HIGH 7.4 cisco ios A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vul 0.3%
CVE-2024-20303 HIGH 7.4 cisco ios_xe A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper ma 0.3%
CVE-2024-20276 HIGH 7.4 cisco ios A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of process-switched traffic. A 0.3%
CVE-2023-51437 HIGH 7.4 apache pulsar Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes th 0.8%
CVE-2023-50178 HIGH 7.4 fortinet fortiadc An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-t 0.2%
CVE-2023-45226 HIGH 7.4 f5 big-ip_next_service_proxy_for_kubernetes The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. 0.4%
CVE-2023-4136 HIGH 7.4 craftercms craftercms Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 1.4%
CVE-2023-36873 HIGH 7.4 microsoft .net_framework .NET Framework Spoofing Vulnerability 1.5%
CVE-2023-36605 HIGH 7.4 microsoft windows_10_1809 Windows Named Pipe Filesystem Elevation of Privilege Vulnerability 0.5%
CVE-2023-34391 HIGH 7.4 selinc sel-5033_acselerator_real-time_automation_controller Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230 0.1%