57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26218 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 12.9% | — |
| CVE-2024-26211 | HIGH 7.8 | microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2024-26199 | HIGH 7.8 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2024-26182 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 5.6% | — |
| CVE-2024-26178 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-26176 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-26175 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-26173 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-26170 | HIGH 7.8 | microsoft windows_10_21h2 Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | 6.6% | — |
| CVE-2024-26169 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 4.0% | |
| CVE-2024-26158 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Install Service Elevation of Privilege Vulnerability | 12.3% | — |
| CVE-2024-23940 | HIGH 7.8 | trendmicro air_support Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library | 0.6% | — |
| CVE-2024-23670 | HIGH 7.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.4% | — |
| CVE-2024-23667 | HIGH 7.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.4% | — |
| CVE-2024-23110 | HIGH 7.8 | fortinet fortios A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafte | 0.3% | — |
| CVE-2024-22705 | HIGH 7.8 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled. | 0.3% | — |
| CVE-2024-22369 | HIGH 7.8 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4. | 0.7% | — |
| CVE-2024-22237 | HIGH 7.8 | vmware aria_operations_for_networks Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system. | 0.2% | — |
| CVE-2024-21892 | HIGH 7.8 | nodejs node.js On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implementation of this excepti | 0.6% | — |
| CVE-2024-21447 | HIGH 7.8 | microsoft windows_10_21h2 Windows Authentication Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2024-21446 | HIGH 7.8 | microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-21442 | HIGH 7.8 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-21437 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 8.0% | — |
| CVE-2024-21436 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-21434 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | 0.8% | — |