IT
56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.794 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-43620 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-43611 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2024-43608 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.3%
CVE-2024-43607 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.3%
CVE-2024-43599 HIGH 8.8 microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability 1.4%
CVE-2024-43593 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.6%
CVE-2024-43592 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.6%
CVE-2024-43589 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.4%
CVE-2024-43564 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.3%
CVE-2024-43549 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.3%
CVE-2024-43533 HIGH 8.8 microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability 1.5%
CVE-2024-43532 HIGH 8.8 microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability 12.0%
CVE-2024-43519 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.4%
CVE-2024-43518 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability 0.9%
CVE-2024-43517 HIGH 8.8 microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability 1.3%
CVE-2024-43488 HIGH 8.8 microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. 1.1%
CVE-2024-43469 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 1.6%
CVE-2024-43462 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-43461 HIGH 8.8 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 54.5%
CVE-2024-43459 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-43455 HIGH 8.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability 1.7%
CVE-2024-43453 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.4%
CVE-2024-43115 HIGH 8.8 apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which 0.5%
CVE-2024-43033 HIGH 8.8 jpress jpress JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is 1.0%
CVE-2024-42362 HIGH 8.8 apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0. 1.3%