56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.705 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2024-26169 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 4.0% | |
| CVE-2024-4577 | CRIT 9.8 | ransomware fedoraproject fedora In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 | 100.0% | |
| CVE-2024-1086 | HIGH 7.8 | ransomware debian debian_linux A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_s | 28.1% | |
| CVE-2020-17519 | HIGH 7.5 | apache flink A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by | 97.9% | |
| CVE-2024-30051 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 5.6% | |
| CVE-2024-30040 | HIGH 8.8 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 3.9% | |
| CVE-2024-29988 | HIGH 8.8 | microsoft windows_10_1809 SmartScreen Prompt Security Feature Bypass Vulnerability | 45.2% | |
| CVE-2024-20359 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l | 19.4% | |
| CVE-2024-20353 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting i | 70.7% | |
| CVE-2022-38028 | HIGH 7.8 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 14.9% | |
| CVE-2024-3400 | CRIT 10.0 | ransomware paloaltonetworks pan-os A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit | 100.0% | |
| CVE-2023-24955 | HIGH 7.2 | ransomware microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 85.4% | |
| CVE-2023-48788 | CRIT 9.8 | ransomware fortinet forticlient_enterprise_management_server A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted pa | 98.4% | |
| CVE-2024-21338 | HIGH 7.8 | ransomware microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 59.8% | |
| CVE-2023-29360 | HIGH 8.4 | microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability | 22.1% | |
| CVE-2024-21410 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 12.7% | |
| CVE-2020-3259 | HIGH 7.5 | ransomware cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could l | 71.8% | |
| CVE-2024-21412 | HIGH 8.1 | ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability | 95.4% | |
| CVE-2024-21351 | HIGH 7.6 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 30.3% | |
| CVE-2024-21762 | CRIT 9.8 | ransomware fortinet fortios A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0 | 84.3% | |
| CVE-2023-4762 | HIGH 8.8 | debian debian_linux Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 39.9% | |
| CVE-2023-34048 | CRIT 9.8 | vmware vcenter_server vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution. | 99.4% | |
| CVE-2023-6549 | HIGH 8.2 | citrix netscaler_application_delivery_controller Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | 57.6% | |
| CVE-2023-6548 | MED 5.5 | citrix netscaler_application_delivery_controller Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf | 3.2% | |
| CVE-2023-29357 | CRIT 9.8 | ransomware microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 100.0% |