IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26826 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data re-injection from stale subflow When the MPTCP PM detects that a subflow is stale, all the packet scheduler must re-inject all the mptcp-level unacked data. To avoid acquirin 0.6% —
CVE-2024-26769 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by defer 0.6% —
CVE-2024-26690 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seq 0.8% —
CVE-2024-26626 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel NULL pointer dereference, address: 0000000000000092 [ 86.306815] #PF: supervisor read ac 0.6% —
CVE-2024-26611 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC XDP Currently when packet is shrunk via bpf_xdp_adjust_tail() and memory type is set to MEM_TYPE_XSK_BUFF_POOL, null ptr dereference happens 0.6% —
CVE-2024-26254 HIGH 7.5 microsoft windows_10_1809 Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability 3.1% —
CVE-2024-26248 HIGH 7.5 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.0% —
CVE-2024-26219 HIGH 7.5 microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability 3.1% —
CVE-2024-26215 HIGH 7.5 microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability 2.7% —
CVE-2024-26212 HIGH 7.5 microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability 62.6% —
CVE-2024-26204 HIGH 7.5 microsoft outlook Outlook for Android Information Disclosure Vulnerability 2.1% —
CVE-2024-26190 HIGH 7.5 microsoft .net Microsoft QUIC Denial of Service Vulnerability 3.0% —
CVE-2024-26026 HIGH 7.5 f5 big-ip_next_central_manager An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 7.2% —
CVE-2024-26013 HIGH 7.5 fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 0.5% —
CVE-2024-26010 HIGH 7.5 fortinet fortios A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7. 0.8% —
CVE-2024-26006 HIGH 7.5 fortinet fortios An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and belo 0.6% —
CVE-2024-25560 HIGH 7.5 f5 big-ip_access_policy_manager When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5% —
CVE-2024-2551 HIGH 7.5 paloaltonetworks pan-os A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. 0.5% —
CVE-2024-2550 HIGH 7.5 paloaltonetworks pan-os A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of serv 0.5% —
CVE-2024-25015 HIGH 7.5 ibm mq IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278. 0.9% —
CVE-2024-24990 HIGH 7.5 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t 0.9% —
CVE-2024-24989 HIGH 7.5 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t 1.1% —
CVE-2024-24775 HIGH 7.5 f5 big-ip_access_policy_manager When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.5% —
CVE-2024-24749 HIGH 7.5 geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi 0.8% —
CVE-2024-24746 HIGH 7.5 apache nimble Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: throu 1.4% —