57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-24778 | MED 6.5 | apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe | 0.7% | — |
| CVE-2024-24683 | MED 6.5 | apache hop_engine Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet pag | 1.2% | — |
| CVE-2024-23953 | MED 6.5 | apache hive Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are r | 1.2% | — |
| CVE-2024-23952 | MED 6.5 | apache superset This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This | 1.7% | — |
| CVE-2024-23669 | MED 6.5 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.5% | — |
| CVE-2024-22340 | MED 6.5 | ibm common_cryptographic_architecture IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | 0.4% | — |
| CVE-2024-21618 | MED 6.5 | juniper junos An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause Denial of Service (DoS). On all Junos OS and | 0.3% | — |
| CVE-2024-21617 | MED 6.5 | juniper junos An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). On all Junos OS platforms, when NSR is enabled, a | 0.3% | — |
| CVE-2024-21613 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). On a | 0.3% | — |
| CVE-2024-21609 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels t | 0.3% | — |
| CVE-2024-21605 | MED 6.5 | juniper junos An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is | 0.3% | — |
| CVE-2024-21603 | MED 6.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service. If a scaled configuration for Source class usage (S | 0.5% | — |
| CVE-2024-21600 | MED 6.5 | juniper junos An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When MPLS packets are mea | 0.3% | — |
| CVE-2024-21599 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If an MX Series device receive | 0.3% | — |
| CVE-2024-21593 | MED 6.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If an attacker sends | 0.3% | — |
| CVE-2024-21587 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeatedly flaps DHCP subsc | 0.3% | — |
| CVE-2024-21424 | MED 6.5 | microsoft azure_compute_gallery Azure Compute Gallery Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2024-21388 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 32.0% | — |
| CVE-2024-21356 | MED 6.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 2.1% | — |
| CVE-2024-21320 | MED 6.5 | microsoft windows_10_1507 Windows Themes Spoofing Vulnerability | 22.8% | — |
| CVE-2024-21314 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.1% | — |
| CVE-2024-20690 | MED 6.5 | microsoft windows_10_1809 Windows Nearby Sharing Spoofing Vulnerability | 1.3% | — |
| CVE-2024-20684 | MED 6.5 | microsoft windows_11_21h2 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-20680 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 2.0% | — |
| CVE-2024-20679 | MED 6.5 | microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability | 1.3% | — |