58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-46863 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, and we test !link->num_adr as a condition to end the loop in hda_sdw_machi | 0.2% | — |
| CVE-2024-46811 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk_tabl | 0.2% | — |
| CVE-2024-46764 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: add check for invalid name in btf_name_valid_section() If the length of the name string is 1 and the value of name[0] is NULL byte, an OOB vulnerability occurs in btf_name_valid_section | 0.2% | — |
| CVE-2024-46743 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: of/irq: Prevent device address out-of-bounds read in interrupt map walk When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells p | 0.3% | — |
| CVE-2024-45331 | HIGH 7.3 | fortinet fortianalyzer A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 | 0.2% | — |
| CVE-2024-44933 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bnxt_en : Fix memory out-of-bounds in bnxt_fill_hw_rss_tbl() A recent commit has modified the code in __bnxt_reserve_rings() to set the default RSS indirection table to default only when the | 0.2% | — |
| CVE-2024-43594 | HIGH 7.3 | microsoft system_center_2019 Microsoft System Center Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2024-43552 | HIGH 7.3 | microsoft windows_11_22h2 Windows Shell Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-43529 | HIGH 7.3 | microsoft windows_10_21h2 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-43495 | HIGH 7.3 | microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-43475 | HIGH 7.3 | microsoft windows_server_2008 Microsoft Windows Admin Center Information Disclosure Vulnerability | 1.8% | — |
| CVE-2024-43470 | HIGH 7.3 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-42093 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask variable on stack is not recommended since it can cause potenti | 0.2% | — |
| CVE-2024-42088 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") removed the codec entry fo | 0.2% | — |
| CVE-2024-41767 | HIGH 7.3 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end databa | 0.3% | — |
| CVE-2024-41056 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files Use strnlen() instead of strlen() on the algorithm and coefficient name string arrays in V1 wmfw files. In V1 wmfw files the | 0.3% | — |
| CVE-2024-40971 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: remove clear SB_INLINECRYPT flag in default_options In f2fs_remount, SB_INLINECRYPT flag will be clear and re-set. If create new file or open file during this gap, these files will not | 0.3% | — |
| CVE-2024-40901 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when using test_bit() on a single word. The test_bit() and set_bit() functions | 0.3% | — |
| CVE-2024-39563 | HIGH 7.3 | juniper junos_space A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the | 1.3% | — |
| CVE-2024-39546 | HIGH 7.3 | juniper junos_os_evolved A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute | 0.2% | — |
| CVE-2024-39472 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f9fe52daa ("xfs: detect and handle invalid iclog size set by mkfs") added a fixup for incorrect h_size values us | 0.3% | — |
| CVE-2024-38659 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: enic: Validate length of nl attributes in enic_set_vf_port enic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE is of length PORT_PROFILE_MAX and that the nl attributes IFLA_PORT | 0.2% | — |
| CVE-2024-38611 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: i2c: et8ek8: Don't strip remove function when driver is builtin Using __exit for the remove function results in the remove callback being discarded with CONFIG_VIDEO_ET8EK8=y. When su | 0.2% | — |
| CVE-2024-38552 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of bounds issue in the color transformation function. The issue could occur when the index | 0.3% | — |
| CVE-2024-38538 | HIGH 7.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's xmit path by sending a short (less than ETH_HLEN bytes) skb. T | 0.3% | — |