57.399 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.399 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-20678 | HIGH 8.8 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2024-20674 | HIGH 8.8 | microsoft windows_10_1507 Windows Kerberos Security Feature Bypass Vulnerability | 17.2% | — |
| CVE-2024-20536 | HIGH 8.8 | cisco nexus_dashboard_fabric_controller A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This | 0.8% | — |
| CVE-2024-20449 | HIGH 8.8 | cisco nexus_dashboard_fabric_controller A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exp | 0.9% | — |
| CVE-2024-20435 | HIGH 8.8 | cisco asyncos A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for t | 0.2% | — |
| CVE-2024-20398 | HIGH 8.8 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user a | 0.2% | — |
| CVE-2024-20393 | HIGH 8.8 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists | 0.6% | — |
| CVE-2024-20381 | HIGH 8.8 | cisco ios_xr A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authentic | 0.6% | — |
| CVE-2024-20360 | HIGH 8.8 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based mana | 0.8% | — |
| CVE-2024-20040 | HIGH 8.8 | google android In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0836015 | 0.2% | — |
| CVE-2024-12284 | HIGH 8.8 | citrix netscaler_agent Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | 13.3% | — |
| CVE-2024-11395 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.4% | — |
| CVE-2024-11112 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | 0.4% | — |
| CVE-2024-0670 | HIGH 8.8 | checkmk checkmk Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges | 0.3% | — |
| CVE-2023-6790 | HIGH 8.8 | paloaltonetworks pan-os A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web inter | 0.7% | — |
| CVE-2023-6753 | HIGH 8.8 | lfprojects mlflow Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. | 1.1% | — |
| CVE-2023-6702 | HIGH 8.8 | fedoraproject fedora Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 43.8% | — |
| CVE-2023-53676 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The function lio_target_nacl_info_show() uses sprintf() in a loop to print details for every iSCSI connection in a ses | 0.3% | — |
| CVE-2023-53675 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible desc_ptr out-of-bounds accesses Sanitize possible desc_ptr out-of-bounds accesses in ses_enclosure_data_process(). | 0.2% | — |
| CVE-2023-53673 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_disconnect, we do hci_conn_del even if disconnection failed. ISO, L2CAP and SCO connections refer to the hci_co | 0.2% | — |
| CVE-2023-53630 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix unpinning of pages when an access is present syzkaller found that the calculation of batch_last_index should use 'start_index' since at input to this function the batch is eithe | 0.2% | — |
| CVE-2023-53615 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix deletion race condition System crash when using debug kernel due to link list corruption. The cause of the link list corruption is due to session deletion was allowed to q | 0.2% | — |
| CVE-2023-53589 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't trust firmware n_channels If the firmware sends us a corrupted MCC response with n_channels much larger than the command response can be, we might copy far too much | 0.2% | — |
| CVE-2023-53586 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix multiple LUN_RESET handling This fixes a bug where an initiator thinks a LUN_RESET has cleaned up running commands when it hasn't. The bug was added in commit 51ec502a3266 | 0.5% | — |
| CVE-2023-53454 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing th | 0.2% | — |