IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-41013 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a directory data block This adds sanity checks for xfs_dir2_data_unused and xfs_dir2_data_entry to make sure don't stray beyond valid memory region. Before pat 0.2% —
CVE-2024-40978 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix crash while reading debugfs attribute The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on a __user pointer, which results into the crash. To fix th 0.3% —
CVE-2024-40930 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate HE operation element parsing Validate that the HE operation element has the correct length before parsing it. 0.2% —
CVE-2024-40929 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids In some versions of cfg80211, the ssids poinet might be a valid one even though n_ssids is 0. Accessing the pointer in this case 0.4% —
CVE-2024-40920 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state to RCU to avoid a vlan use-after-free but forgot to change the vlan group dereference helper. Swit 0.4% —
CVE-2024-39804 HIGH 7.1 microsoft powerpoint A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to t 0.9% —
CVE-2024-39499 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() a 0.3% —
CVE-2024-39487 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() In function bond_option_arp_ip_targets_set(), if newval->string is an empty string, newval->string+1 will point to the byt 0.2% —
CVE-2024-39483 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked When requesting an NMI window, WARN on vNMI support being enabled if and only if NMIs are actually masked, i.e. if the vCPU i 0.2% —
CVE-2024-39469 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() when a directory folio/page read fails is incorrect, as in the old ext2 implemen 0.2% —
CVE-2024-38832 HIGH 7.1 vmware aria_operations VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. 0.4% —
CVE-2024-38621 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: stk1160: fix bounds checking in stk1160_copy_video() The subtract in this condition is reversed. The ->length is the length of the buffer. The ->bytesused is how many bytes we have 0.3% —
CVE-2024-38606 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate slices count returned by FW The function adf_send_admin_tl_start() enables the telemetry (TL) feature on a QAT device by sending the ICP_QAT_FW_TL_START message to the 0.2% —
CVE-2024-38590 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Modify the print level of CQE error Too much print may lead to a panic in kernel. Change ibdev_err() to ibdev_err_ratelimited(), and change the printing level of cqe dump to debug 0.3% —
CVE-2024-38585 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tools/nolibc/stdlib: fix memory error in realloc() Pass user_p_len to memcpy() instead of heap->len to prevent realloc() from copying an extra sizeof(heap) bytes from beyond the allocated re 0.2% —
CVE-2024-38560 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Ensure the copied buf is NUL terminated Currently, we allocate a nbytes-sized kernel buffer and copy nbytes from userspace to that buffer. Later, we use sscanf on this buffer but 0.3% —
CVE-2024-38188 HIGH 7.1 microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability 0.6% —
CVE-2024-38170 HIGH 7.1 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8% —
CVE-2024-38097 HIGH 7.1 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.6% —
CVE-2024-38032 HIGH 7.1 microsoft windows_10_21h2 Microsoft Xbox Remote Code Execution Vulnerability 1.0% —
CVE-2024-37966 HIGH 7.1 microsoft sql_server_2017 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability 2.2% —
CVE-2024-37342 HIGH 7.1 microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability 1.7% —
CVE-2024-37337 HIGH 7.1 microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Information Disclosure Vulnerability 1.7% —
CVE-2024-36960 HIGH 7.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to th 0.3% —
CVE-2024-36935 HIGH 7.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ice: ensure the copied buf is NUL terminated Currently, we allocate a count-sized kernel buffer and copy count bytes from userspace to that buffer. Later, we use sscanf on this buffer but we 0.2% —