IT
57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38231 MED 6.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability 1.9%
CVE-2024-38230 MED 6.5 microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability 2.4%
CVE-2024-38222 MED 6.5 microsoft edge Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.2%
CVE-2024-38219 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.9%
CVE-2024-38214 MED 6.5 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability 1.6%
CVE-2024-38213 MED 6.5 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 13.6%
CVE-2024-38200 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 20.3%
CVE-2024-38197 MED 6.5 microsoft teams Microsoft Teams for iOS Spoofing Vulnerability 16.1%
CVE-2024-38167 MED 6.5 microsoft .net .NET and Visual Studio Information Disclosure Vulnerability 1.4%
CVE-2024-38165 MED 6.5 microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability 1.3%
CVE-2024-38105 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-38102 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-38101 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-38048 MED 6.5 microsoft windows_10_1507 Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability 1.0%
CVE-2024-38030 MED 6.5 microsoft windows_10_1507 Windows Themes Spoofing Vulnerability 51.1%
CVE-2024-38027 MED 6.5 microsoft windows_10_1507 Windows Line Printer Daemon Service Denial of Service Vulnerability 1.0%
CVE-2024-38020 MED 6.5 microsoft 365_apps Microsoft Outlook Spoofing Vulnerability 1.8%
CVE-2024-36504 MED 6.5 fortinet fortios An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web p 0.7%
CVE-2024-34457 MED 6.5 apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 0.7%
CVE-2024-33502 MED 6.5 fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 1.3%
CVE-2024-32761 MED 6.5 f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of 0.5%
CVE-2024-32760 MED 6.5 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. 0.9%
CVE-2024-31867 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to 1.2%
CVE-2024-31865 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar 1.7%
CVE-2024-31860 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0 1.4%