IT
56.801 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.801 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26186 HIGH 8.8 microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability 1.6%
CVE-2024-26179 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2024-26166 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.0%
CVE-2024-26165 HIGH 8.8 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 1.9%
CVE-2024-26164 HIGH 8.8 microsoft django_backend Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability 2.1%
CVE-2024-26162 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2024-26161 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2024-26159 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.9%
CVE-2024-25938 HIGH 8.8 foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and r 15.6%
CVE-2024-25744 HIGH 8.8 linux linux_kernel In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c. 0.3%
CVE-2024-25648 HIGH 8.8 foxit pdf_editor A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and 15.6%
CVE-2024-25575 HIGH 8.8 foxit pdf_editor A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result 17.7%
CVE-2024-23755 HIGH 8.8 clickup clickup ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode. 1.1%
CVE-2024-23668 HIGH 8.8 fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL 0.7%
CVE-2024-23663 HIGH 8.8 fortinet fortiextender_firmware An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request. 0.6%
CVE-2024-23321 HIGH 8.8 apache rocketmq For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user pr 0.9%
CVE-2024-23320 HIGH 8.8 apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we 1.4%
CVE-2024-22014 HIGH 8.8 360totalsecurity 360_total_security An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. 0.8%
CVE-2024-21756 HIGH 8.8 fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized 2.2%
CVE-2024-21755 HIGH 8.8 fortinet fortisandbox A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized 2.5%
CVE-2024-21620 HIGH 8.8 juniper junos An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker 0.9%
CVE-2024-21451 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.9%
CVE-2024-21450 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.0%
CVE-2024-21449 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-21444 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%