57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-39532 | MED 6.3 | juniper junos An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to access sensitive information. When another user performs a specific operation, s | 0.2% | — |
| CVE-2024-38311 | MED 6.3 | apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fi | 0.9% | — |
| CVE-2024-38207 | MED 6.3 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.4% | — |
| CVE-2024-36071 | MED 6.3 | samsung magician Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path. | 0.1% | — |
| CVE-2024-35970 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: af_unix: Clear stale u->oob_skb. syzkaller started to report deadlock of unix_gc_lock after commit 4090fa373f0e ("af_unix: Replace garbage collection algorithm."), but it just uncovers the b | 0.5% | — |
| CVE-2024-32638 | MED 6.3 | apache apisix Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, wh | 1.1% | — |
| CVE-2024-30045 | MED 6.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-28898 | MED 6.3 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-27032 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential panic during recovery During recovery, if FAULT_BLOCK is on, it is possible that f2fs_reserve_new_block() will return -ENOSPC during recovery, then it may trigge | 0.3% | — |
| CVE-2024-24795 | MED 6.3 | apache http_server HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixe | 2.9% | — |
| CVE-2024-23672 | MED 6.3 | apache tomcat Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, fro | 2.3% | — |
| CVE-2024-22351 | MED 6.3 | ibm infosphere_information_server IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | 0.2% | — |
| CVE-2024-22099 | MED 6.3 | linux linux_kernel NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12 | 0.6% | — |
| CVE-2024-20675 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-20491 | MED 6.3 | cisco nexus_dashboard_fabric_controller A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log | 0.3% | — |
| CVE-2024-20490 | MED 6.3 | cisco nexus_dashboard_fabric_controller A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because | 0.3% | — |
| CVE-2024-20448 | MED 6.3 | cisco nexus_dashboard_fabric_controller A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper | 0.1% | — |
| CVE-2024-20438 | MED 6.3 | cisco nexus_dashboard A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoint | 0.4% | — |
| CVE-2024-20280 | MED 6.3 | cisco ucs_central_software A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness | 0.1% | — |
| CVE-2024-1883 | MED 6.3 | papercut papercut_mf This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potenti | 61.5% | — |
| CVE-2024-0129 | MED 6.3 | nvidia nemo NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering. | 0.2% | — |
| CVE-2024-0085 | MED 6.3 | nvidia cloud_gaming NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of servi | 0.1% | — |
| CVE-2024-0009 | MED 6.3 | paloaltonetworks pan-os An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address. | 0.2% | — |
| CVE-2023-52644 | MED 6.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled When QoS is disabled, the queue priority value will not map to the correct ieee80211 queue since there is only one queu | 0.2% | — |
| CVE-2023-52581 | MED 6.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255 elements expired we're supposed to switch to a new gc container structure. This never happens: u8 ty | 0.3% | — |