57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-23111 | MED 6.8 | fortinet fortios An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reb | 1.0% | — |
| CVE-2024-21429 | MED 6.8 | microsoft windows_10_1507 Windows USB Hub Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-21381 | MED 6.8 | microsoft azure_active_directory Microsoft Azure Active Directory B2C Spoofing Vulnerability | 0.4% | — |
| CVE-2024-21341 | MED 6.8 | microsoft windows_10_1809 Windows Kernel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-21319 | MED 6.8 | microsoft .net Microsoft Identity Denial of service vulnerability | 2.9% | — |
| CVE-2024-20524 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.5% | — |
| CVE-2024-20523 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.5% | — |
| CVE-2024-20517 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.4% | — |
| CVE-2024-20516 | MED 6.8 | cisco rv042_firmware A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to cause an unexpected reload of an affected device, resulting in a denial | 0.4% | — |
| CVE-2024-20391 | MED 6.8 | cisco secure_client A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a | 0.3% | — |
| CVE-2024-20331 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent us | 0.7% | — |
| CVE-2024-20307 | MED 6.8 | cisco ios A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, f | 0.7% | — |
| CVE-2024-20277 | MED 6.8 | cisco thousandeyes_enterprise_agent A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability i | 0.8% | — |
| CVE-2024-0565 | MED 6.8 | linux linux_kernel An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service. | 2.0% | — |
| CVE-2024-0007 | MED 6.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another | 0.4% | — |
| CVE-2023-51751 | MED 6.8 | scalefusion scalefusion ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode. | 0.2% | — |
| CVE-2023-43125 | MED 6.8 | f5 big-ip_access_policy_manager BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.2% | — |
| CVE-2023-38738 | MED 6.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of s | 0.5% | — |
| CVE-2023-38729 | MED 6.8 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT. | 0.6% | — |
| CVE-2023-36697 | MED 6.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2023-35629 | MED 6.8 | microsoft windows_10_1507 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-35332 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Protocol Security Feature Bypass | 0.5% | — |
| CVE-2023-33153 | MED 6.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-32043 | MED 6.8 | microsoft windows_10_1507 Windows Remote Desktop Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-30576 | MED 6.8 | apache guacamole Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process. | 1.1% | — |