56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38240 | HIGH 8.1 | microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2024-38229 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38176 | HIGH 8.1 | microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38045 | HIGH 8.1 | microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-37325 | HIGH 8.1 | microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-36263 | HIGH 8.1 | apache submarine ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we | 1.0% | — |
| CVE-2024-36032 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in case | 0.4% | — |
| CVE-2024-35937 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to | 0.3% | — |
| CVE-2024-35279 | HIGH 8.1 | fortinet fortios A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP cont | 1.0% | — |
| CVE-2024-35264 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2024-30188 | HIGH 8.1 | apache dolphinscheduler File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which f | 6.0% | — |
| CVE-2024-30020 | HIGH 8.1 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-29995 | HIGH 8.1 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2024-28746 | HIGH 8.1 | apache airflow Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. Users of Apache Airf | 1.3% | — |
| CVE-2024-27782 | HIGH 8.1 | fortinet fortiaiops Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests. | 0.7% | — |
| CVE-2024-26954 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op | 0.7% | — |
| CVE-2024-26736 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verificatio | 0.7% | — |
| CVE-2024-26009 | HIGH 8.1 | fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, Fo | 0.6% | — |
| CVE-2024-25710 | HIGH 8.1 | apache commons_compress Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue. | 0.4% | — |
| CVE-2024-23671 | HIGH 8.1 | fortinet fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or comm | 1.2% | — |
| CVE-2024-23106 | HIGH 8.1 | fortinet forticlientems An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS r | 1.0% | — |
| CVE-2024-22273 | HIGH 8.1 | vmware cloud_foundation The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or e | 0.2% | — |
| CVE-2024-22259 | HIGH 8.1 | netapp active_iq_unified_manager Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/def | 2.6% | — |
| CVE-2024-21416 | HIGH 8.1 | microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-21412 | HIGH 8.1 | ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability | 95.4% |