IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-55955 MED 6.7 trendmicro deep_security_agent An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtai 0.1%
CVE-2024-54025 MED 6.7 fortinet fortiisolator An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI reques 0.4%
CVE-2024-52968 MED 6.7 fortinet forticlient An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. 0.2%
CVE-2024-49044 MED 6.7 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.8%
CVE-2024-47495 MED 6.7 juniper junos_os_evolved An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in use on Juniper Networks Junos OS Evolved devices. This issue 0.2%
CVE-2024-46663 MED 6.7 fortinet fortimail A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. 0.2%
CVE-2024-45325 MED 6.7 fortinet fortiddos-f An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands 0.5%
CVE-2024-43646 MED 6.7 microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.5%
CVE-2024-43645 MED 6.7 microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability 0.5%
CVE-2024-43631 MED 6.7 microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.5%
CVE-2024-40587 MED 6.7 fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or 0.6%
CVE-2024-40586 MED 6.7 fortinet forticlient An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe. 0.2%
CVE-2024-38668 MED 6.7 intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. 0.2%
CVE-2024-38383 MED 6.7 intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access. 0.2%
CVE-2024-38173 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0.7%
CVE-2024-38013 MED 6.7 microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability 0.6%
CVE-2024-37983 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-37982 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-37979 MED 6.7 microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2024-37976 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-36253 MED 6.7 intel server_debug_and_provisioning_tool Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access. 0.2%
CVE-2024-35201 MED 6.7 intel server_debug_and_provisioning_tool Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. 0.1%
CVE-2024-33503 MED 6.7 fortinet fortianalyzer A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 0.2%
CVE-2024-32123 MED 6.7 fortinet fortianalyzer Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6. 0.4%
CVE-2024-32118 MED 6.7 fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. 0.6%