58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26209 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 14.8% | — |
| CVE-2024-26207 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26181 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-26177 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 1.1% | — |
| CVE-2024-26174 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.9% | — |
| CVE-2024-26172 | MED 5.5 | microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-26160 | MED 5.5 | microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 11.4% | — |
| CVE-2024-25741 | MED 5.5 | linux linux_kernel printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact. | 0.3% | — |
| CVE-2024-25740 | MED 5.5 | linux linux_kernel A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. | 0.2% | — |
| CVE-2024-25739 | MED 5.5 | linux linux_kernel create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size. | 0.2% | — |
| CVE-2024-25142 | MED 5.5 | apache airflow Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of | 0.3% | — |
| CVE-2024-2431 | MED 5.5 | paloaltonetworks globalprotect An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode. | 0.2% | — |
| CVE-2024-23851 | MED 5.5 | linux linux_kernel copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because of a missing param_kernel->data_size check. This is related to ctl_ioctl. | 0.3% | — |
| CVE-2024-23850 | MED 5.5 | linux linux_kernel In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation. | 0.3% | — |
| CVE-2024-23849 | MED 5.5 | linux linux_kernel In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access. | 0.3% | — |
| CVE-2024-23848 | MED 5.5 | linux linux_kernel In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. | 0.3% | — |
| CVE-2024-23607 | MED 5.5 | f5 f5os-a A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2024-23441 | MED 5.5 | anti-virus vba32 Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver. | 0.2% | — |
| CVE-2024-23107 | MED 5.5 | fortinet fortiweb An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrat | 0.2% | — |
| CVE-2024-21753 | MED 5.5 | fortinet forticlient_endpoint_management_server A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker t | 0.7% | — |
| CVE-2024-21594 | MED 5.5 | juniper junos A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS). On an SRX 5000 Series device, when executing a specific comm | 0.2% | — |
| CVE-2024-21408 | MED 5.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 4.5% | — |
| CVE-2024-21377 | MED 5.5 | microsoft windows_10_1507 Windows DNS Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-21362 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability | 0.4% | — |
| CVE-2024-21311 | MED 5.5 | microsoft windows_10_1507 Windows Cryptographic Services Information Disclosure Vulnerability | 0.8% | — |