58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2024-28901 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-28900 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-28899 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2024-28898 | MED 6.3 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-28897 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-28896 | HIGH 7.5 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-28889 | MED 5.9 | f5 big-ip_access_policy_manager When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi | 0.4% | — |
| CVE-2024-28883 | HIGH 7.4 | f5 big-ip_access_policy_manager An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support ( | 0.2% | — |
| CVE-2024-2881 | MED 6.7 | wolfssl wolfssl Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges | 0.5% | — |
| CVE-2024-28793 | MED 4.9 | ibm engineering_workflow_management IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall | 0.3% | — |
| CVE-2024-28786 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | 0.2% | — |
| CVE-2024-28780 | MED 5.9 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-28778 | MED 6.5 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization. | 0.5% | — |
| CVE-2024-28777 | HIGH 8.8 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the un | 0.6% | — |
| CVE-2024-28776 | MED 5.4 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to | 0.2% | — |
| CVE-2024-28775 | MED 4.4 | ibm websphere_automation IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi | 0.4% | — |
| CVE-2024-28764 | MED 6.5 | ibm websphere_automation IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. | 0.2% | — |
| CVE-2024-28752 | CRIT 9.3 | apache cxf A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the d | 2.5% | — |
| CVE-2024-28746 | HIGH 8.1 | apache airflow Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access. Users of Apache Airf | 1.3% | — |
| CVE-2024-28168 | HIGH 7.5 | apache formatting_objects_processor Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue. | 1.0% | — |
| CVE-2024-28148 | MED 4.3 | apache superset An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, wh | 0.7% | — |
| CVE-2024-28132 | MED 4.4 | f5 big-ip_next_cloud-native_network_functions Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.2% | — |
| CVE-2024-28098 | MED 6.4 | apache pulsar The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super | 1.7% | — |
| CVE-2024-27906 | MED 5.9 | apache airflow Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version | 0.3% | — |
| CVE-2024-27905 | CRIT 9.1 | apache aurora ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a | 1.5% | — |