56.801 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.801 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26186 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26179 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-26166 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-26165 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2024-26164 | HIGH 8.8 | microsoft django_backend Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-26162 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-26161 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2024-26159 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2024-25938 | HIGH 8.8 | foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and r | 15.6% | — |
| CVE-2024-25744 | HIGH 8.8 | linux linux_kernel In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c. | 0.3% | — |
| CVE-2024-25648 | HIGH 8.8 | foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and | 15.6% | — |
| CVE-2024-25575 | HIGH 8.8 | foxit pdf_editor A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result | 17.7% | — |
| CVE-2024-23755 | HIGH 8.8 | clickup clickup ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode. | 1.1% | — |
| CVE-2024-23668 | HIGH 8.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.7% | — |
| CVE-2024-23663 | HIGH 8.8 | fortinet fortiextender_firmware An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request. | 0.6% | — |
| CVE-2024-23321 | HIGH 8.8 | apache rocketmq For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user pr | 0.9% | — |
| CVE-2024-23320 | HIGH 8.8 | apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we | 1.4% | — |
| CVE-2024-22014 | HIGH 8.8 | 360totalsecurity 360_total_security An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. | 0.8% | — |
| CVE-2024-21756 | HIGH 8.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized | 2.2% | — |
| CVE-2024-21755 | HIGH 8.8 | fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized | 2.5% | — |
| CVE-2024-21620 | HIGH 8.8 | juniper junos An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker | 0.9% | — |
| CVE-2024-21451 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2024-21450 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-21449 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-21444 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |