IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.960 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-49119 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.2%
CVE-2024-49118 HIGH 8.1 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.4%
CVE-2024-49116 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 10.0%
CVE-2024-49115 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2024-49108 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.2%
CVE-2024-49106 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.2%
CVE-2024-49057 HIGH 8.1 microsoft defender_for_endpoint Microsoft Defender for Endpoint on Android Spoofing Vulnerability 1.7%
CVE-2024-49048 HIGH 8.1 microsoft torchgeo TorchGeo Remote Code Execution Vulnerability 1.2%
CVE-2024-47571 HIGH 8.1 fortinet fortimanager An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. 0.9%
CVE-2024-46858 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== 0.6%
CVE-2024-45217 HIGH 8.1 apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that 0.7%
CVE-2024-45106 HIGH 8.1 apache ozone Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. T 0.6%
CVE-2024-45033 HIGH 8.1 apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insuf 1.0%
CVE-2024-44986 HIGH 8.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m 0.7%
CVE-2024-44973 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm, slub: do not call do_slab_free for kfence object In 782f8906f805 the freeing of kfence objects was moved from deep inside do_slab_free to the wrapper functions outside. This is a nice ch 0.4%
CVE-2024-43878 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When there is a misconfiguration of input state slow path KASAN report error. Fix this error. west login: [ 52.987278] eth1: renamed from veth11 [ 0.4%
CVE-2024-43625 HIGH 8.1 microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability 0.7%
CVE-2024-43598 HIGH 8.1 microsoft lightgbm LightGBM Remote Code Execution Vulnerability 1.4%
CVE-2024-43582 HIGH 8.1 microsoft windows_10_1809 Remote Desktop Protocol Server Remote Code Execution Vulnerability 3.2%
CVE-2024-43460 HIGH 8.1 microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. 0.7%
CVE-2024-43447 HIGH 8.1 microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability 1.4%
CVE-2024-41107 HIGH 8.1 apache cloudstack The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication 17.8%
CVE-2024-40941 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't read past the mfuart notifcation In case the firmware sends a notification that claims it has more data than it has, we will read past that was allocated for the no 0.4%
CVE-2024-39747 HIGH 8.1 ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality. 0.8%
CVE-2024-38473 HIGH 8.1 apache http_server Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, wh 25.9%