IT
58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.254 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-38206 HIGH 8.5 microsoft copilot_studio An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. 12.3% —
CVE-2024-38204 HIGH 7.5 microsoft azure_functions Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. 0.9% —
CVE-2024-38203 MED 6.2 microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability 0.7% —
CVE-2024-38202 HIGH 7.3 microsoft windows_10_1607 Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization 1.7% —
CVE-2024-38201 HIGH 7.0 microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability 0.6% —
CVE-2024-38200 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 20.5% —
CVE-2024-38199 CRIT 9.8 microsoft windows_10_1507 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability 2.2% —
CVE-2024-38198 HIGH 7.5 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 0.8% —
CVE-2024-38197 MED 6.5 microsoft teams Microsoft Teams for iOS Spoofing Vulnerability 16.1% —
CVE-2024-38196 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 6.0% —
CVE-2024-38195 HIGH 7.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 0.5% —
CVE-2024-38194 HIGH 8.4 microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. 1.3% —
CVE-2024-38191 HIGH 7.8 microsoft windows_10_1607 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 0.5% —
CVE-2024-38190 HIGH 8.6 microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. 1.1% —
CVE-2024-38188 HIGH 7.1 microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability 0.6% —
CVE-2024-38187 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1% —
CVE-2024-38186 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0.8% —
CVE-2024-38185 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1% —
CVE-2024-38184 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.2% —
CVE-2024-38183 CRIT 9.8 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. 0.8% —
CVE-2024-38182 CRIT 9.0 microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. 0.9% —
CVE-2024-38180 HIGH 8.8 microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability 1.6% —
CVE-2024-38179 HIGH 8.8 microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability 0.4% —
CVE-2024-38177 HIGH 7.8 microsoft app_installer Windows App Installer Spoofing Vulnerability 0.9% —
CVE-2024-38176 HIGH 8.1 microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. 0.9% —