57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49105 | HIGH 8.4 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-49063 | HIGH 8.4 | microsoft muzic Microsoft/Muzic Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-46831 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: Fix use-after-free error in kunit test This is a clear use-after-free error. We remove it, and rely on checking the return code of vcap_del_rule. | 0.2% | — |
| CVE-2024-46823 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kunit/overflow: Fix UB in overflow_allocation_test The 'device_name' array doesn't exist out of the 'overflow_allocation_test' function scope. However, it is being used as a driver name when | 0.3% | — |
| CVE-2024-43497 | HIGH 8.4 | microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-39480 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buff | 0.3% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.6% | — |
| CVE-2024-38194 | HIGH 8.4 | microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | 1.3% | — |
| CVE-2024-37984 | HIGH 8.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-36973 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function g | 0.2% | — |
| CVE-2024-36910 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Don't free decrypted memory In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned | 0.2% | — |
| CVE-2024-35987 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: riscv: Fix loading 64-bit NOMMU kernels past the start of RAM commit 3335068f8721 ("riscv: Use PUD/P4D/PGD pages for the linear mapping") added logic to allow using RAM below the kernel load | 0.2% | — |
| CVE-2024-35980 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Fix TLBI RANGE operand KVM/arm64 relies on TLBI RANGE feature to flush TLBs when the dirty pages are collected by VMM and the page table entries become write protected during liv | 0.2% | — |
| CVE-2024-35875 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don't rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model mea | 0.3% | — |
| CVE-2024-30381 | HIGH 8.4 | juniper paragon_active_assurance_control_center An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a network-adjacent attacker with root access to a Test Agent Appliance the ability to access sensitive information ab | 0.5% | — |
| CVE-2024-29989 | HIGH 8.4 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-29050 | HIGH 8.4 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-27317 | HIGH 8.4 | apache pulsar In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. | 56.9% | — |
| CVE-2024-26945 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix nr_cpus < nr_iaa case If nr_cpus < nr_iaa, the calculated cpus_per_iaa will be 0, which causes a divide-by-0 in rebalance_wq_table(). Make sure cpus_per_iaa is 1 in that c | 0.2% | — |
| CVE-2024-26927 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Add some bounds checking to firmware data Smatch complains about "head->full_size - head->header_size" can underflow. To some extent, we're always going to have to trust the firm | 0.3% | — |
| CVE-2024-26830 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: i40e: Do not allow untrusted VF to remove administratively set MAC Currently when PF administratively sets VF's MAC address and the VF is put down (VF tries to delete all MACs) then the MAC | 0.2% | — |
| CVE-2024-23537 | HIGH 8.4 | apache fineract Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue. | 1.1% | — |
| CVE-2024-21760 | HIGH 8.4 | fortinet fortisoar An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitra | 0.8% | — |
| CVE-2024-20489 | HIGH 8.4 | cisco ios_xr A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database cred | 0.1% | — |
| CVE-2023-53598 | HIGH 8.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Range check CHDBOFF and ERDBOFF If the value read from the CHDBOFF and ERDBOFF registers is outside the range of the MHI register space then an invalid address might be compu | 0.2% | — |