57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49053 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 Sales Spoofing Vulnerability | 0.6% | — |
| CVE-2024-48988 | HIGH 7.6 | apache streampark SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (Sprin | 0.6% | — |
| CVE-2024-47714 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: use hweight16 to get correct tx antenna The chainmask is u16 so using hweight8 cannot get correct tx_ant. Without this patch, the tx_ant of band 2 would be -1 and lead to | 0.3% | — |
| CVE-2024-43579 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43578 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43476 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2024-43474 | HIGH 7.6 | microsoft sql_server_2017 Microsoft SQL Server Information Disclosure Vulnerability | 1.3% | — |
| CVE-2024-42133 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Ignore too large handle values in BIG hci_le_big_sync_established_evt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be e | 0.3% | — |
| CVE-2024-42132 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caus | 0.3% | — |
| CVE-2024-36968 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. M | 0.3% | — |
| CVE-2024-3661 | HIGH 7.6 | cisco anyconnect_vpn_client DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network c | 4.1% | — |
| CVE-2024-35267 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-35266 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-30048 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-30047 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-27783 | HIGH 7.6 | fortinet fortiaiops Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious | 0.3% | — |
| CVE-2024-21419 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2024-21396 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability | 1.2% | — |
| CVE-2024-21394 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability | 1.1% | — |
| CVE-2024-21393 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.2% | — |
| CVE-2024-21389 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.2% | — |
| CVE-2024-21351 | HIGH 7.6 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 30.3% | |
| CVE-2024-21328 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability | 1.3% | — |
| CVE-2024-21327 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | 1.3% | — |
| CVE-2024-0715 | HIGH 7.6 | hitachi global_link_manager Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03. | 0.5% | — |