57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-39745 | MED 5.9 | ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.3% | — |
| CVE-2024-39559 | MED 5.9 | juniper junos_os_evolved An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS Evolved may allow a network-based unauthenticated attacker to crash the device (vmcore) by sending a specific TCP packet over an established | 0.4% | — |
| CVE-2024-39554 | MED 5.9 | juniper junos A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attack | 0.4% | — |
| CVE-2024-38320 | MED 5.9 | ibm storage_protect IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-38264 | MED 5.9 | microsoft windows_11_22h2 Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability | 1.3% | — |
| CVE-2024-38103 | MED 5.9 | microsoft edge Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.5% | — |
| CVE-2024-38099 | MED 5.9 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 1.3% | — |
| CVE-2024-37985 | MED 5.9 | microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-33864 | MED 5.9 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript. | 0.5% | — |
| CVE-2024-31487 | MED 5.9 | fortinet fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all ve | 0.9% | — |
| CVE-2024-30402 | MED 5.9 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When teleme | 0.5% | — |
| CVE-2024-30401 | MED 5.9 | juniper junos An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, MX304, and EX9200-15C, may allow an attacker to exploit a stack-based buffer overflo | 0.6% | — |
| CVE-2024-30046 | MED 5.9 | microsoft .net Visual Studio Denial of Service Vulnerability | 1.7% | — |
| CVE-2024-29120 | MED 5.9 | apache streampark In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's u | 0.3% | — |
| CVE-2024-28889 | MED 5.9 | f5 big-ip_access_policy_manager When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi | 0.4% | — |
| CVE-2024-28780 | MED 5.9 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-27906 | MED 5.9 | apache airflow Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version | 0.3% | — |
| CVE-2024-26578 | MED 5.9 | apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. | 0.9% | — |
| CVE-2024-23945 | MED 5.9 | apache hive Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities a | 1.5% | — |
| CVE-2024-23665 | MED 5.9 | fortinet fortiweb Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM | 0.5% | — |
| CVE-2024-22251 | MED 5.9 | vmware fusion VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclos | 0.2% | — |
| CVE-2024-21601 | MED 5.9 | juniper junos A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of | 0.5% | — |
| CVE-2024-21585 | MED 5.9 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's control, to flap BGP sessio | 0.6% | — |
| CVE-2024-21344 | MED 5.9 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.7% | — |
| CVE-2024-21343 | MED 5.9 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.8% | — |