56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.580 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-27315 | MED 4.3 | apache superset An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surf | 1.0% | — |
| CVE-2024-26196 | MED 4.3 | microsoft edge Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-26188 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.8% | — |
| CVE-2024-26167 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0.9% | — |
| CVE-2024-26016 | MED 4.3 | apache superset A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these ch | 0.9% | — |
| CVE-2024-25037 | MED 4.3 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. | 0.6% | — |
| CVE-2024-24772 | MED 4.3 | apache superset A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to | 0.9% | — |
| CVE-2024-2433 | MED 4.3 | paloaltonetworks pan-os An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th | 0.6% | — |
| CVE-2024-22256 | MED 4.3 | vmware cloud_director VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance. | 0.4% | — |
| CVE-2024-22241 | MED 4.3 | vmware aria_operations_for_networks Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account. | 37.8% | — |
| CVE-2024-21761 | MED 4.3 | fortinet fortiportal An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload. | 0.4% | — |
| CVE-2024-21759 | MED 4.3 | fortinet fortiportal An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.0.6 allows attacker to view unauthorized resources via HTTP or HTTPS requests. | 0.3% | — |
| CVE-2024-21610 | MED 4.3 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). In a scaled CoS sce | 0.5% | — |
| CVE-2024-21382 | MED 4.3 | microsoft edge_chromium Microsoft Edge for Android Information Disclosure Vulnerability | 0.9% | — |
| CVE-2024-20507 | MED 4.3 | cisco meeting_management A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of sensitive information with | 0.4% | — |
| CVE-2024-20497 | MED 4.3 | cisco expressway-e A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. | 0.3% | — |
| CVE-2024-20487 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by t | 0.3% | — |
| CVE-2024-20476 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-side validation of Ad | 0.4% | — |
| CVE-2024-20474 | MED 4.3 | cisco anyconnect_secure_mobility_client A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflo | 0.6% | — |
| CVE-2024-20434 | MED 4.3 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag inform | 0.3% | — |
| CVE-2024-20347 | MED 4.3 | cisco emergency_responder A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for | 0.2% | — |
| CVE-2024-20333 | MED 4.3 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device. This vulnerability is due to insuffi | 0.4% | — |
| CVE-2024-20319 | MED 4.3 | cisco ios_xr A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected device. | 0.3% | — |
| CVE-2024-20283 | MED 4.3 | cisco nexus_dashboard A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit | 0.4% | — |
| CVE-2024-20279 | MED 4.3 | cisco application_policy_infrastructure_controller A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) poli | 0.3% | — |