58.202 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.202 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-50566 | HIGH 7.2 | fortinet fortimanager A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 th | 1.1% | — |
| CVE-2024-49091 | HIGH 7.2 | microsoft windows_server_2012 Windows Domain Name Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-49089 | HIGH 7.2 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-49042 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2024-48889 | HIGH 7.2 | fortinet fortimanager An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiMa | 1.7% | — |
| CVE-2024-45844 | HIGH 7.2 | f5 big-ip_access_policy_manager BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 10.6% | — |
| CVE-2024-45330 | HIGH 7.2 | fortinet fortianalyzer A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. | 0.6% | — |
| CVE-2024-45324 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b | 0.7% | — |
| CVE-2024-43613 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2024-43464 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 36.3% | — |
| CVE-2024-42062 | HIGH 7.2 | apache cloudstack CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an ac | 0.9% | — |
| CVE-2024-41746 | HIGH 7.2 | ibm cics_tx IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo | 0.2% | — |
| CVE-2024-40584 | HIGH 7.2 | fortinet fortianalyzer An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13 | 2.0% | — |
| CVE-2024-38239 | HIGH 7.2 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2024-38228 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.2% | — |
| CVE-2024-38227 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 8.2% | — |
| CVE-2024-38094 | HIGH 7.2 | ransomware microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 50.9% | |
| CVE-2024-38044 | HIGH 7.2 | microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38028 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38025 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38024 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 45.2% | — |
| CVE-2024-38023 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 52.9% | — |
| CVE-2024-38019 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-36512 | HIGH 7.2 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized cod | 1.4% | — |
| CVE-2024-35273 | HIGH 7.2 | fortinet fortianalyzer A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests. | 0.7% | — |