58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-29217 | MED 4.6 | apache answer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal | 1.0% | — |
| CVE-2024-29195 | MED 6.0 | microsoft azure_c_shared_utility The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocatio | 5.0% | — |
| CVE-2024-29178 | HIGH 8.8 | apache streampark On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigat | 1.2% | — |
| CVE-2024-29133 | MED 5.4 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 1.7% | — |
| CVE-2024-29131 | HIGH 7.3 | apache commons_configuration Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | 2.1% | — |
| CVE-2024-29120 | MED 5.9 | apache streampark In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's u | 0.3% | — |
| CVE-2024-29072 | HIGH 8.2 | foxit pdf_editor A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. A low privilege user can trigger the update action which can result | 0.5% | — |
| CVE-2024-29070 | CRIT 9.1 | apache streampark On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even af | 0.8% | — |
| CVE-2024-29066 | HIGH 7.2 | microsoft windows_server_2008 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-29064 | MED 6.2 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-29063 | HIGH 7.3 | microsoft azure_ai_search Azure AI Search Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-29062 | HIGH 7.1 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-29061 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-29060 | MED 6.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-29057 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2024-29056 | MED 4.3 | microsoft windows_server_2008 Windows Authentication Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-29055 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-29054 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-29053 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2024-29052 | HIGH 7.8 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-29050 | HIGH 8.4 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-29049 | MED 4.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | 0.7% | — |
| CVE-2024-29048 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-29047 | HIGH 8.8 | microsoft sql_server_2019 Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-29046 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |