58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43567 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-43566 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-43565 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43562 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43545 | HIGH 7.5 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43544 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43541 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-43521 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.4% | — |
| CVE-2024-43515 | HIGH 7.5 | microsoft windows_10_1507 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-43506 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Denial of Service Vulnerability | 2.3% | — |
| CVE-2024-43499 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.6% | — |
| CVE-2024-43485 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3.1% | — |
| CVE-2024-43484 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2.9% | — |
| CVE-2024-43483 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2.9% | — |
| CVE-2024-43477 | HIGH 7.5 | microsoft entra_id Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. | 1.0% | — |
| CVE-2024-43467 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-43452 | HIGH 7.5 | microsoft windows_10_1809 Windows Registry Elevation of Privilege Vulnerability | 28.1% | — |
| CVE-2024-43450 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.6% | — |
| CVE-2024-43394 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro | 1.1% | — |
| CVE-2024-43204 | HIGH 7.5 | apache http_server SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header w | 0.8% | — |
| CVE-2024-42516 | HIGH 7.5 | apache http_server HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 b | 0.7% | — |
| CVE-2024-42361 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL | 1.1% | — |
| CVE-2024-42286 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: validate nvme_local_port correctly The driver load failed with error message, qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef and with a kernel crash, | 0.9% | — |
| CVE-2024-42256 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make cifs repick the server for the op before re | 0.7% | — |
| CVE-2024-42247 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel warnings because swap_endian() tries to load a 128-bit IPv6 address from an una | 0.7% | — |