58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30043 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 54.7% | — |
| CVE-2024-30036 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability | 2.3% | — |
| CVE-2024-30019 | MED 6.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.6% | — |
| CVE-2024-30011 | MED 6.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.6% | — |
| CVE-2024-29987 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-28786 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | 0.2% | — |
| CVE-2024-28778 | MED 6.5 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization. | 0.5% | — |
| CVE-2024-28764 | MED 6.5 | ibm websphere_automation IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623. | 0.2% | — |
| CVE-2024-27439 | MED 6.5 | apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo | 0.7% | — |
| CVE-2024-27028 | MED 6.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: spi: spi-mt65xx: Fix NULL pointer access in interrupt handler The TX buffer in spi_transfer can be a NULL pointer, so the interrupt handler may end up writing to the invalid memory and cause | 1.2% | — |
| CVE-2024-26886 | MED 6.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: af_bluetooth: Fix deadlock Attemting to do sock_lock on .recvmsg may cause a deadlock as shown bellow, so instead of using sock_sock this uses sk_receive_queue.lock on bt_sock_ioc | 0.5% | — |
| CVE-2024-26226 | MED 6.5 | microsoft windows_server_2008 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 1.8% | — |
| CVE-2024-26197 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.8% | — |
| CVE-2024-26185 | MED 6.5 | microsoft windows_11_22h2 Windows Compressed Folder Tampering Vulnerability | 30.3% | — |
| CVE-2024-26183 | MED 6.5 | microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-24916 | MED 6.5 | checkpoint smartconsole Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin). | 2.7% | — |
| CVE-2024-24778 | MED 6.5 | apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe | 0.7% | — |
| CVE-2024-24683 | MED 6.5 | apache hop_engine Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet pag | 1.2% | — |
| CVE-2024-23953 | MED 6.5 | apache hive Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are r | 1.2% | — |
| CVE-2024-23952 | MED 6.5 | apache superset This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This | 1.7% | — |
| CVE-2024-23669 | MED 6.5 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.5% | — |
| CVE-2024-22340 | MED 6.5 | ibm common_cryptographic_architecture IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | 0.4% | — |
| CVE-2024-21618 | MED 6.5 | juniper junos An Access of Memory Location After End of Buffer vulnerability in the Layer-2 Control Protocols Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause Denial of Service (DoS). On all Junos OS and | 0.3% | — |
| CVE-2024-21617 | MED 6.5 | juniper junos An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). On all Junos OS platforms, when NSR is enabled, a | 0.3% | — |
| CVE-2024-21613 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS). On a | 0.3% | — |