58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-41013 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a directory data block This adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry to make sure don't stray beyond valid memory region. Before pat | 0.2% | — |
| CVE-2024-40978 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix crash while reading debugfs attribute The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on a __user pointer, which results into the crash. To fix th | 0.3% | — |
| CVE-2024-40930 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate HE operation element parsing Validate that the HE operation element has the correct length before parsing it. | 0.2% | — |
| CVE-2024-40929 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids In some versions of cfg80211, the ssids poinet might be a valid one even though n_ssids is 0. Accessing the pointer in this case | 0.4% | — |
| CVE-2024-40920 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state to RCU to avoid a vlan use-after-free but forgot to change the vlan group dereference helper. Swit | 0.4% | — |
| CVE-2024-39804 | HIGH 7.1 | microsoft powerpoint A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to t | 0.9% | — |
| CVE-2024-39499 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() a | 0.3% | — |
| CVE-2024-39487 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() In function bond_option_arp_ip_targets_set(), if newval->string is an empty string, newval->string+1 will point to the byt | 0.2% | — |
| CVE-2024-39483 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked When requesting an NMI window, WARN on vNMI support being enabled if and only if NMIs are actually masked, i.e. if the vCPU i | 0.2% | — |
| CVE-2024-39469 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() when a directory folio/page read fails is incorrect, as in the old ext2 implemen | 0.2% | — |
| CVE-2024-38832 | HIGH 7.1 | vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | 0.4% | — |
| CVE-2024-38621 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: stk1160: fix bounds checking in stk1160_copy_video() The subtract in this condition is reversed. The ->length is the length of the buffer. The ->bytesused is how many bytes we have | 0.3% | — |
| CVE-2024-38606 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate slices count returned by FW The function adf_send_admin_tl_start() enables the telemetry (TL) feature on a QAT device by sending the ICP_QAT_FW_TL_START message to the | 0.2% | — |
| CVE-2024-38590 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Modify the print level of CQE error Too much print may lead to a panic in kernel. Change ibdev_err() to ibdev_err_ratelimited(), and change the printing level of cqe dump to debug | 0.3% | — |
| CVE-2024-38585 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of heap->len to prevent realloc() from copying an extra sizeof(heap) bytes from beyond the allocated re | 0.2% | — |
| CVE-2024-38560 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but | 0.3% | — |
| CVE-2024-38188 | HIGH 7.1 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38170 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38097 | HIGH 7.1 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38032 | HIGH 7.1 | microsoft windows_10_21h2 Microsoft Xbox Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-37966 | HIGH 7.1 | microsoft sql_server_2017 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-37342 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-37337 | HIGH 7.1 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-36960 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to th | 0.3% | — |
| CVE-2024-36935 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ice: ensure the copied buf is NUL terminated Currently, we allocate a count-sized kernel buffer and copy count bytes from userspace to that buffer. Later, we use sscanf on this buffer but we | 0.2% | — |