57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38129 | HIGH 7.5 | microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-38126 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2024-38119 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38112 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability | 84.2% | |
| CVE-2024-38095 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.7% | — |
| CVE-2024-38091 | HIGH 7.5 | microsoft windows_10_1507 Microsoft WS-Discovery Denial of Service Vulnerability | 1.9% | — |
| CVE-2024-38078 | HIGH 7.5 | microsoft windows_11_21h2 Xbox Wireless Adapter Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38073 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38072 | HIGH 7.5 | microsoft windows_server_2016 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38071 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 35.9% | — |
| CVE-2024-38068 | HIGH 7.5 | microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38067 | HIGH 7.5 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38064 | HIGH 7.5 | microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability | 2.2% | — |
| CVE-2024-38061 | HIGH 7.5 | microsoft windows_10_1507 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2024-38031 | HIGH 7.5 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38029 | HIGH 7.5 | microsoft windows_server_2022_23h2 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-38015 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 2.4% | — |
| CVE-2024-37968 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.0% | — |
| CVE-2024-36991 | HIGH 7.5 | splunk splunk In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows. | 13.0% | — |
| CVE-2024-36962 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver uses local_bh_disable()/local_bh_enable() in its IRQ handler to avoid triggering net_rx_action() so | 0.5% | — |
| CVE-2024-36945 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable resolved by ip_route_output_flow() are not released or | 0.5% | — |
| CVE-2024-36929 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb | 0.9% | — |
| CVE-2024-36471 | HIGH 7.5 | apache allura Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allur | 0.8% | — |
| CVE-2024-36052 | HIGH 7.5 | rarlab winrar RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. | 0.7% | — |
| CVE-2024-35999 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb3: missing lock when picking channel Coverity spotted a place where we should have been holding the channel lock when accessing the ses channel index. Addresses-Coverity: 1582039 ("Data | 0.4% | — |