57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-55955 | MED 6.7 | trendmicro deep_security_agent An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtai | 0.1% | — |
| CVE-2024-54025 | MED 6.7 | fortinet fortiisolator An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI reques | 0.4% | — |
| CVE-2024-52968 | MED 6.7 | fortinet forticlient An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. | 0.2% | — |
| CVE-2024-49044 | MED 6.7 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-47495 | MED 6.7 | juniper junos_os_evolved An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing Engines (REs) are in use on Juniper Networks Junos OS Evolved devices. This issue | 0.2% | — |
| CVE-2024-46663 | MED 6.7 | fortinet fortimail A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | 0.2% | — |
| CVE-2024-45325 | MED 6.7 | fortinet fortiddos-f An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands | 0.5% | — |
| CVE-2024-43646 | MED 6.7 | microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-43645 | MED 6.7 | microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-43631 | MED 6.7 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-40587 | MED 6.7 | fortinet fortivoice An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or | 0.6% | — |
| CVE-2024-40586 | MED 6.7 | fortinet forticlient An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe. | 0.2% | — |
| CVE-2024-38668 | MED 6.7 | intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2024-38383 | MED 6.7 | intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2024-38173 | MED 6.7 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38013 | MED 6.7 | microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-37983 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37982 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37979 | MED 6.7 | microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-37976 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-36253 | MED 6.7 | intel server_debug_and_provisioning_tool Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2024-35201 | MED 6.7 | intel server_debug_and_provisioning_tool Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | 0.1% | — |
| CVE-2024-33503 | MED 6.7 | fortinet fortianalyzer A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 | 0.2% | — |
| CVE-2024-32123 | MED 6.7 | fortinet fortianalyzer Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6. | 0.4% | — |
| CVE-2024-32118 | MED 6.7 | fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. | 0.6% | — |