56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49119 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49118 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-49116 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 10.0% | — |
| CVE-2024-49115 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49108 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49106 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49057 | HIGH 8.1 | microsoft defender_for_endpoint Microsoft Defender for Endpoint on Android Spoofing Vulnerability | 1.7% | — |
| CVE-2024-49048 | HIGH 8.1 | microsoft torchgeo TorchGeo Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-47571 | HIGH 8.1 | fortinet fortimanager An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. | 0.9% | — |
| CVE-2024-46858 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== | 0.6% | — |
| CVE-2024-45217 | HIGH 8.1 | apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that | 0.7% | — |
| CVE-2024-45106 | HIGH 8.1 | apache ozone Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. T | 0.6% | — |
| CVE-2024-45033 | HIGH 8.1 | apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insuf | 1.0% | — |
| CVE-2024-44986 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m | 0.7% | — |
| CVE-2024-44973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm, slub: do not call do_slab_free for kfence object In 782f8906f805 the freeing of kfence objects was moved from deep inside do_slab_free to the wrapper functions outside. This is a nice ch | 0.4% | — |
| CVE-2024-43878 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When there is a misconfiguration of input state slow path KASAN report error. Fix this error. west login: [ 52.987278] eth1: renamed from veth11 [ | 0.4% | — |
| CVE-2024-43625 | HIGH 8.1 | microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-43598 | HIGH 8.1 | microsoft lightgbm LightGBM Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43582 | HIGH 8.1 | microsoft windows_10_1809 Remote Desktop Protocol Server Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2024-43460 | HIGH 8.1 | microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-43447 | HIGH 8.1 | microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-41107 | HIGH 8.1 | apache cloudstack The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication | 17.8% | — |
| CVE-2024-40941 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't read past the mfuart notifcation In case the firmware sends a notification that claims it has more data than it has, we will read past that was allocated for the no | 0.4% | — |
| CVE-2024-39747 | HIGH 8.1 | ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. | 0.8% | — |
| CVE-2024-38473 | HIGH 8.1 | apache http_server Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, wh | 25.9% | — |