58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26826 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data re-injection from stale subflow When the MPTCP PM detects that a subflow is stale, all the packet scheduler must re-inject all the mptcp-level unacked data. To avoid acquirin | 0.6% | — |
| CVE-2024-26769 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by defer | 0.6% | — |
| CVE-2024-26690 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seq | 0.8% | — |
| CVE-2024-26626 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel NULL pointer dereference, address: 0000000000000092 [ 86.306815] #PF: supervisor read ac | 0.6% | — |
| CVE-2024-26611 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC XDP Currently when packet is shrunk via bpf_xdp_adjust_tail() and memory type is set to MEM_TYPE_XSK_BUFF_POOL, null ptr dereference happens | 0.6% | — |
| CVE-2024-26254 | HIGH 7.5 | microsoft windows_10_1809 Microsoft Virtual Machine Bus (VMBus) Denial of Service Vulnerability | 3.1% | — |
| CVE-2024-26248 | HIGH 7.5 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-26219 | HIGH 7.5 | microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability | 3.1% | — |
| CVE-2024-26215 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.7% | — |
| CVE-2024-26212 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 62.6% | — |
| CVE-2024-26204 | HIGH 7.5 | microsoft outlook Outlook for Android Information Disclosure Vulnerability | 2.1% | — |
| CVE-2024-26190 | HIGH 7.5 | microsoft .net Microsoft QUIC Denial of Service Vulnerability | 3.0% | — |
| CVE-2024-26026 | HIGH 7.5 | f5 big-ip_next_central_manager An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 7.2% | — |
| CVE-2024-26013 | HIGH 7.5 | fortinet fortianalyzer A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 | 0.5% | — |
| CVE-2024-26010 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7. | 0.8% | — |
| CVE-2024-26006 | HIGH 7.5 | fortinet fortios An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and belo | 0.6% | — |
| CVE-2024-25560 | HIGH 7.5 | f5 big-ip_access_policy_manager When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2024-2551 | HIGH 7.5 | paloaltonetworks pan-os A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. | 0.5% | — |
| CVE-2024-2550 | HIGH 7.5 | paloaltonetworks pan-os A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of serv | 0.5% | — |
| CVE-2024-25015 | HIGH 7.5 | ibm mq IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278. | 0.9% | — |
| CVE-2024-24990 | HIGH 7.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t | 0.9% | — |
| CVE-2024-24989 | HIGH 7.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer t | 1.1% | — |
| CVE-2024-24775 | HIGH 7.5 | f5 big-ip_access_policy_manager When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 0.5% | — |
| CVE-2024-24749 | HIGH 7.5 | geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi | 0.8% | — |
| CVE-2024-24746 | HIGH 7.5 | apache nimble Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: throu | 1.4% | — |