IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26622 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control() Since tomoyo_write_control() updates head->write_buf when write() of long lines is requested, we need to fetch head->write_buf after head- 0.2%
CVE-2024-26619 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: riscv: Fix module loading free order Reverse order of kfree calls to resolve use-after-free error. 0.3%
CVE-2024-26617 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: move mmu notification mechanism inside mm lock Move mmu notification mechanism inside mm lock to prevent race condition in other components which depend on it. The notifie 0.2%
CVE-2024-26616 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: scrub: avoid use-after-free when chunk length is not 64K aligned [BUG] There is a bug report that, on a ext4-converted btrfs, scrub leads to various problems, including: - "unable to 0.3%
CVE-2024-26614 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tcp: make sure init the accept_queue's spinlocks once When I run syz's reproduction C program locally, it causes the following issue: pvqspinlock: lock 0xffff9d181cd5c660 has corrupted value 0.2%
CVE-2024-26610 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix a memory corruption iwl_fw_ini_trigger_tlv::data is a pointer to a __le32, which means that if we copy to iwl_fw_ini_trigger_tlv::data + offset while offset is in bytes, w 0.3%
CVE-2024-26608 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix global oob in ksmbd_nl_policy Similar to a reported issue (check the commit b33fb5b801c6 ("net: qualcomm: rmnet: fix global oob in rmnet_policy"), my local fuzzer finds another gl 0.2%
CVE-2024-26601 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit 6bd97bf273bd ("ext4: remove redundant mb_regenerate_buddy()") and reintroduces mb_regenerate_b 0.3%
CVE-2024-26599 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2 args->args[2] is not defined. Actually the flags are contained in args->args[1]. 0.3%
CVE-2024-26597 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_policy The variable rmnet_link_ops assign a *bigger* maxtype which leads to a global out-of-bounds read when parsing the netlink attributes. See 0.3%
CVE-2024-26589 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS For PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off for validation. However, variable offset ptr alu is not prohibited for 0.2%
CVE-2024-26588 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access The test_tag test triggers an unhandled page fault: # ./test_tag [ 130.640218] CPU 0 Unable to handle kernel paging request at virtu 0.2%
CVE-2024-26586 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. The group contains a li 0.2%
CVE-2024-26581 HIGH 7.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval e 2.2%
CVE-2024-26257 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.0%
CVE-2024-26256 HIGH 7.8 fedoraproject fedora Libarchive Remote Code Execution Vulnerability 84.8%
CVE-2024-26245 HIGH 7.8 microsoft windows_10_1507 Windows SMB Elevation of Privilege Vulnerability 0.7%
CVE-2024-26241 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0.7%
CVE-2024-26239 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 0.6%
CVE-2024-26238 HIGH 7.8 microsoft windows_10_21h2 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability 0.8%
CVE-2024-26237 HIGH 7.8 microsoft windows_10_1809 Windows Defender Credential Guard Elevation of Privilege Vulnerability 0.7%
CVE-2024-26235 HIGH 7.8 microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability 0.6%
CVE-2024-26230 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 24.1%
CVE-2024-26229 HIGH 7.8 microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability 9.4%
CVE-2024-26228 HIGH 7.8 microsoft windows_10_1507 Windows Cryptographic Services Security Feature Bypass Vulnerability 0.4%