IT
58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.290 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2024-29997 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.9% —
CVE-2024-29996 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 3.4% —
CVE-2024-29995 HIGH 8.1 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.5% —
CVE-2024-29994 HIGH 7.8 microsoft windows_10_1809 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability 0.7% —
CVE-2024-29993 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 2.0% —
CVE-2024-29992 MED 5.5 microsoft azure_identity Azure Identity Library for .NET Information Disclosure Vulnerability 0.7% —
CVE-2024-29991 MED 5.0 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0.6% —
CVE-2024-29990 CRIT 9.0 microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 18.0% —
CVE-2024-29989 HIGH 8.4 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.7% —
CVE-2024-29987 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.2% —
CVE-2024-29986 MED 5.4 microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability 0.5% —
CVE-2024-29985 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4% —
CVE-2024-29984 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4% —
CVE-2024-29983 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4% —
CVE-2024-29982 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4% —
CVE-2024-29981 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.7% —
CVE-2024-29869 MED 5.5 apache hive Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into t 0.3% —
CVE-2024-29868 CRIT 9.1 apache streampipes Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over th 6.0% —
CVE-2024-29834 MED 6.4 apache pulsar This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the t 1.4% —
CVE-2024-29831 HIGH 8.8 apache dolphinscheduler Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2. 1.2% —
CVE-2024-2975 HIGH 8.8 octopus octopus_server A race condition was identified through which privilege escalation was possible in certain configurations. 0.4% —
CVE-2024-29737 MED 4.7 apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to 1.1% —
CVE-2024-29736 CRIT 9.1 apache cxf A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured. 1.0% —
CVE-2024-29735 MED 5.3 apache airflow Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set permissions for all parent folders of log folder, in default configur 1.5% —
CVE-2024-29733 LOW 2.7 apache apache-airflow-providers-ftp Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.crea 0.6% —