56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.794 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43620 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43611 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-43608 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-43607 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-43599 | HIGH 8.8 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43593 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43592 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43589 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43564 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-43549 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-43533 | HIGH 8.8 | microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-43532 | HIGH 8.8 | microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability | 12.0% | — |
| CVE-2024-43519 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43518 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-43517 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-43488 | HIGH 8.8 | microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | 1.1% | — |
| CVE-2024-43469 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43462 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43461 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 54.5% | |
| CVE-2024-43459 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-43455 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability | 1.7% | — |
| CVE-2024-43453 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43115 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which | 0.5% | — |
| CVE-2024-43033 | HIGH 8.8 | jpress jpress JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is | 1.0% | — |
| CVE-2024-42362 | HIGH 8.8 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0. | 1.3% | — |