IT
58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26882 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1 0.7%
CVE-2024-26857 HIGH 7.3 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: geneve: make sure to pull inner header in geneve_rx() syzbot triggered a bug in geneve_rx() [1] Issue is similar to the one I fixed in commit 8d975c15c0cd ("ip6_tunnel: make sure to pull in 0.6%
CVE-2024-26730 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can 0.2%
CVE-2024-26232 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0.9%
CVE-2024-26216 HIGH 7.3 microsoft windows_server_2008 Windows File Server Resource Management Service Elevation of Privilege Vulnerability 0.9%
CVE-2024-26203 HIGH 7.3 microsoft azure_data_studio Azure Data Studio Elevation of Privilege Vulnerability 0.9%
CVE-2024-24910 HIGH 7.3 checkpoint identity_agent A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute 0.2%
CVE-2024-23769 HIGH 7.3 samsung magician Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data. 0.2%
CVE-2024-21443 HIGH 7.3 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 1.3%
CVE-2024-21409 HIGH 7.3 microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability 2.5%
CVE-2024-21329 HIGH 7.3 microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability 1.1%
CVE-2024-20697 HIGH 7.3 microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability 72.2%
CVE-2024-20696 HIGH 7.3 microsoft windows_10_1809 Windows libarchive Remote Code Execution Vulnerability 3.1%
CVE-2024-20430 HIGH 7.3 cisco meraki_systems_manager A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges.  This vulnerability is due to incorrect handling of directory search paths at runtim 0.2%
CVE-2024-20338 HIGH 7.3 cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A 0.9%
CVE-2024-20272 HIGH 7.3 cisco unity_connection A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due t 1.6%
CVE-2024-12753 HIGH 7.3 foxit pdf_editor Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code o 0.3%
CVE-2024-12672 HIGH 7.3 rockwellautomation arena A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To 0.2%
CVE-2024-11364 HIGH 7.3 rockwellautomation arena Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor c 0.3%
CVE-2024-0819 HIGH 7.3 teamviewer remote Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a l 0.2%
CVE-2024-0259 HIGH 7.3 fortra robot_schedule Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, 0.3%
CVE-2023-5450 HIGH 7.3 f5 big-ip_access_policy_manager An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process.  Note: Software versions which have reached End of Technical Support (EoTS) 0.1%
CVE-2023-53640 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: lpass: Fix for KASAN use_after_free out of bounds When we run syzkaller we get below Out of Bounds error. "KASAN: slab-out-of-bounds Read in regcache_flat_read" Below is the backtrac 0.2%
CVE-2023-53500 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: fix slab-use-after-free in decode_session6 When the xfrm device is set to the qdisc of the sfb type, the cb field of the sent skb may be modified during enqueuing. Then, slab-use-after 0.2%
CVE-2023-53205 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target 0.2%