IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.855 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-41723 MED 4.3 f5 big-ip_access_policy_manager Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.3%
CVE-2024-39887 MED 4.3 apache superset An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorizat 4.4%
CVE-2024-39744 MED 4.3 ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. 0.2%
CVE-2024-38808 MED 4.3 netapp active_iq_unified_manager In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application 0.6%
CVE-2024-38221 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-38093 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-38083 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-37070 MED 4.3 ibm concert IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system. 0.3%
CVE-2024-35278 MED 4.3 fortinet fortiportal A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting 0.4%
CVE-2024-33510 MED 4.3 fortinet fortios An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2. 0.6%
CVE-2024-32124 MED 4.3 fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions logging component may allow a remote authenticated read-only attacker to alter logs via a crafted HTTP request. 0.3%
CVE-2024-31979 MED 4.3 apache streampipes Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements. These endpoints we 0.7%
CVE-2024-31869 MED 4.3 apache airflow Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provide 1.0%
CVE-2024-31495 MED 4.3 fortinet fortiportal A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.0.0 through 7.0.6 and version 7.2.0 allows privileged user to obtain unauthorized information via the report download functionality. 0.5%
CVE-2024-31490 MED 4.3 fortinet fortisandbox An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2.2 through 3.2.4, FortiSandbox 3.1.5 allows attacker to i 0.5%
CVE-2024-29981 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.7%
CVE-2024-29057 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.0%
CVE-2024-29056 MED 4.3 microsoft windows_server_2008 Windows Authentication Elevation of Privilege Vulnerability 1.0%
CVE-2024-28148 MED 4.3 apache superset An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, wh 0.7%
CVE-2024-27315 MED 4.3 apache superset An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surf 1.0%
CVE-2024-26196 MED 4.3 microsoft edge Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability 1.2%
CVE-2024-26188 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.8%
CVE-2024-26167 MED 4.3 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 0.9%
CVE-2024-26016 MED 4.3 apache superset A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these ch 0.9%
CVE-2024-25037 MED 4.3 ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. 0.6%