IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38165 MED 6.5 microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability 1.3% —
CVE-2024-38105 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8% —
CVE-2024-38102 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8% —
CVE-2024-38101 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8% —
CVE-2024-38048 MED 6.5 microsoft windows_10_1507 Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability 1.0% —
CVE-2024-38030 MED 6.5 microsoft windows_10_1507 Windows Themes Spoofing Vulnerability 51.1% —
CVE-2024-38027 MED 6.5 microsoft windows_10_1507 Windows Line Printer Daemon Service Denial of Service Vulnerability 1.0% —
CVE-2024-38020 MED 6.5 microsoft 365_apps Microsoft Outlook Spoofing Vulnerability 1.8% —
CVE-2024-36504 MED 6.5 fortinet fortios An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web p 0.7% —
CVE-2024-34457 MED 6.5 apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 0.7% —
CVE-2024-33502 MED 6.5 fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 1.3% —
CVE-2024-32761 MED 6.5 f5 big-ip_access_policy_manager Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of 0.5% —
CVE-2024-32760 MED 6.5 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. 0.9% —
CVE-2024-31867 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can execute malicious queries by setting improper configuration properties to LDAP search filter. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to 1.2% —
CVE-2024-31865 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar 1.7% —
CVE-2024-31860 MED 6.5 apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0 1.4% —
CVE-2024-31493 MED 6.5 fortinet fortisoar An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-tex 0.5% —
CVE-2024-31391 MED 6.5 apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica 0.8% —
CVE-2024-31141 MED 6.5 apache kafka Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these 1.2% —
CVE-2024-30403 MED 6.5 juniper junos_os_evolved A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When Layer 2 traffic is sent through a logical interface, MAC 0.3% —
CVE-2024-30388 MED 6.5 juniper junos An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). If a specific malfo 0.3% —
CVE-2024-30387 MED 6.5 juniper junos A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). If an interface flaps while the system gathers st 0.2% —
CVE-2024-30380 MED 6.5 juniper junos An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS), which causes the l2cpd process to crash by sending a specific TLV. T 0.3% —
CVE-2024-30054 MED 6.5 microsoft powerbi-javascript Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability 1.7% —
CVE-2024-30053 MED 6.5 microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability 1.0% —