58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38165 | MED 6.5 | microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability | 1.3% | — |
| CVE-2024-38105 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-38102 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-38101 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-38048 | MED 6.5 | microsoft windows_10_1507 Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-38030 | MED 6.5 | microsoft windows_10_1507 Windows Themes Spoofing Vulnerability | 51.1% | — |
| CVE-2024-38027 | MED 6.5 | microsoft windows_10_1507 Windows Line Printer Daemon Service Denial of Service Vulnerability | 1.0% | — |
| CVE-2024-38020 | MED 6.5 | microsoft 365_apps Microsoft Outlook Spoofing Vulnerability | 1.8% | — |
| CVE-2024-36504 | MED 6.5 | fortinet fortios An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web p | 0.7% | — |
| CVE-2024-34457 | MED 6.5 | apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | 0.7% | — |
| CVE-2024-33502 | MED 6.5 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 | 1.3% | — |
| CVE-2024-32761 | MED 6.5 | f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of | 0.5% | — |
| CVE-2024-32760 | MED 6.5 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. | 0.9% | — |
| CVE-2024-31867 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to | 1.2% | — |
| CVE-2024-31865 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar | 1.7% | — |
| CVE-2024-31860 | MED 6.5 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access. This issue affects Apache Zeppelin: from 0.9.0 before 0 | 1.4% | — |
| CVE-2024-31493 | MED 6.5 | fortinet fortisoar An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-tex | 0.5% | — |
| CVE-2024-31391 | MED 6.5 | apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica | 0.8% | — |
| CVE-2024-31141 | MED 6.5 | apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these | 1.2% | — |
| CVE-2024-30403 | MED 6.5 | juniper junos_os_evolved A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When Layer 2 traffic is sent through a logical interface, MAC | 0.3% | — |
| CVE-2024-30388 | MED 6.5 | juniper junos An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malfo | 0.3% | — |
| CVE-2024-30387 | MED 6.5 | juniper junos A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while the system gathers st | 0.2% | — |
| CVE-2024-30380 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS), which causes the l2cpd process to crash by sending a specific TLV. T | 0.3% | — |
| CVE-2024-30054 | MED 6.5 | microsoft powerbi-javascript Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-30053 | MED 6.5 | microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability | 1.0% | — |