IT
58.273 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.273 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2024-38472 HIGH 7.5 apache http_server SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access 69.5% —
CVE-2024-3841 MED 6.1 fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) 0.7% —
CVE-2024-38390 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails Calling a6xx_destroy() before adreno_gpu_init() leads to a null pointer dereference on: msm_gpu_cleanup() : platform_se 0.2% —
CVE-2024-38388 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup Use the control private_free callback to free the associated data block. This ensures that the memory won't leak, whatever way the 0.2% —
CVE-2024-38385 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_find() while neither holding sparse_irq_ 0.2% —
CVE-2024-38384 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued __blkcg_rstat_flush() can be run anytime, especially when blk_cgroup_bio_start is being executed. If WRITE of `->lqueued` is 0.2% —
CVE-2024-38383 MED 6.7 intel quartus_prime Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access. 0.2% —
CVE-2024-38381 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be validated header siz 0.4% —
CVE-2024-38379 MED 4.8 apache allura Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted. This issue affects Apache Allu 0.7% —
CVE-2024-38346 CRIT 9.8 apache cloudstack The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities 3.3% —
CVE-2024-38337 CRIT 9.1 ibm sterling_secure_proxy IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitive information contents due to incorrect permission assignments. 0.5% —
CVE-2024-38320 MED 5.9 ibm storage_protect IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.2% —
CVE-2024-38311 MED 6.3 apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fi 0.9% —
CVE-2024-38306 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent buffer folios [BUG] Since v6.8 there are rare kernel crashes reported by various people, the common factor is bad page status error messag 0.1% —
CVE-2024-38286 HIGH 8.6 apache tomcat Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time 1.7% —
CVE-2024-38265 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.4% —
CVE-2024-38264 MED 5.9 microsoft windows_11_22h2 Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability 1.3% —
CVE-2024-38263 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.2% —
CVE-2024-38262 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.1% —
CVE-2024-38261 HIGH 7.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 0.9% —
CVE-2024-38260 HIGH 8.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.6% —
CVE-2024-38259 HIGH 8.8 microsoft windows_11_21h2 Microsoft Management Console Remote Code Execution Vulnerability 1.9% —
CVE-2024-38258 MED 6.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability 4.7% —
CVE-2024-38257 HIGH 7.5 microsoft windows_10_1607 Microsoft AllJoyn API Information Disclosure Vulnerability 4.5% —
CVE-2024-38256 MED 5.5 microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability 0.7% —