| | CVE-2024-37965 | Microsoft | high | 8.8 | 1.7%
| | Microsoft SQL Server Elevation of Privilege Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37342 | Microsoft | high | 7.1 | 1.7%
| | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37341 | Microsoft | high | 8.8 | 1.4%
| | Microsoft SQL Server Elevation of Privilege Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37340 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37339 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37338 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37337 | Microsoft | high | 7.1 | 1.7%
| | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-37335 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-26191 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-26186 | Microsoft | high | 8.8 | 1.6%
| | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | Sep 10, 2024 | Aug 10, 2026 |
| | CVE-2024-31490 | Fortinet | medium | 4.3 | 0.7%
| | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox… | Sep 10, 2024 | Jan 14, 2026 |
| | CVE-2024-42024 | Veeam | high | 8.8 | — | | A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credent… | Sep 7, 2024 | Apr 28, 2025 |
| | CVE-2024-42023 | Veeam | high | 8.8 | — | | An improper access control vulnerability allows low-privileged users to execute code with Administra… | Sep 7, 2024 | Apr 28, 2025 |
| | CVE-2024-42022 | Veeam | medium | 5.3 | — | | An incorrect permission assignment vulnerability allows an attacker to modify product configuration … | Sep 7, 2024 | Apr 28, 2025 |
| | CVE-2024-42021 | Veeam | medium | 6.5 | — | | An improper access control vulnerability allows an attacker with valid access tokens to access saved… | Sep 7, 2024 | Apr 28, 2025 |
| | CVE-2024-42020 | Veeam | medium | 5.4 | — | | A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection… | Sep 7, 2024 | Oct 27, 2024 |
| | CVE-2024-42019 | Veeam | high | 8.0 | — | | A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service servic… | Sep 7, 2024 | May 1, 2025 |
| | CVE-2024-40714 | Veeam | high | 8.3 | — | | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on… | Sep 7, 2024 | May 1, 2025 |
| | CVE-2024-40713 | Veeam | high | 7.8 | — | | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup &… | Sep 7, 2024 | May 1, 2025 |
| | CVE-2024-40712 | Veeam | high | 7.8 | — | | A path traversal vulnerability allows an attacker with a low-privileged account and local access to … | Sep 7, 2024 | May 1, 2025 |
| | CVE-2024-40711 | Veeam | critical | 9.8 | — | | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthentica… | Sep 7, 2024 | Oct 30, 2025 |
| | CVE-2024-40710 | Veeam | high | 8.8 | — | | A series of related high-severity vulnerabilities, the most notable enabling remote code execution (… | Sep 7, 2024 | May 1, 2025 |
| | CVE-2024-39718 | Veeam | high | 8.1 | — | | An improper input validation vulnerability that allows a low-privileged user to remotely remove file… | Sep 7, 2024 | May 8, 2025 |
| | CVE-2024-7885 | Apache | high | 7.5 | 2.6%
| | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuil… | Aug 21, 2024 | Aug 7, 2026 |
| | CVE-2024-22477 | ForgeRock | low | 1.8 | — | | A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The … | Jul 9, 2024 | Nov 21, 2024 |
| | CVE-2024-22377 | ForgeRock | medium | 5.3 | — | | The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. | Jul 9, 2024 | Nov 21, 2024 |
| | CVE-2024-27785 | Fortinet | medium | 5.4 | 0.6%
| | An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet Fo… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27784 | Fortinet | high | 8.8 | 0.6%
| | Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerabili… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27783 | Fortinet | high | 7.6 | 1.1%
| | Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27782 | Fortinet | high | 8.1 | 0.8%
| | Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-35260 | Microsoft | high | 8.0 | 1.0%
| | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse … | Jun 27, 2024 | Jul 20, 2026 |
| | CVE-2024-38093 | Microsoft | medium | 4.3 | 0.5%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jun 20, 2024 | Jul 20, 2026 |
| | CVE-2024-38082 | Microsoft | medium | 4.7 | 0.5%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jun 20, 2024 | Jul 20, 2026 |
| | CVE-2024-37079 | VMware | critical | 9.8 | 82.7%
| ⚠ KEV | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. … | Jun 18, 2024 | Jan 26, 2026 |
| | CVE-2024-38083 | Microsoft | medium | 4.3 | 0.5%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jun 13, 2024 | Jul 20, 2026 |
| | CVE-2024-30058 | Microsoft | medium | 5.4 | 0.4%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jun 13, 2024 | Jul 20, 2026 |
| | CVE-2024-30057 | Microsoft | medium | 5.4 | 0.4%
| | Microsoft Edge for iOS Spoofing Vulnerability | Jun 13, 2024 | Jul 20, 2026 |
| | CVE-2024-36265 | Apache | critical | 9.8 | 0.7%
| | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Cor… | Jun 12, 2024 | Jul 14, 2026 |
| | CVE-2024-37325 | Microsoft | high | 8.1 | 1.1%
| | Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35263 | Microsoft | medium | 5.7 | 1.7%
| | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35255 | Microsoft | medium | 5.5 | 0.8%
| | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35254 | Microsoft | high | 7.1 | 0.8%
| | Azure Monitor Agent Elevation of Privilege Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35253 | Microsoft | medium | 4.4 | 0.7%
| | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35252 | Microsoft | high | 7.5 | 2.5%
| | Azure Storage Movement Client Library Denial of Service Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-35249 | Microsoft | high | 8.8 | 3.4%
| | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | Jun 11, 2024 | Aug 10, 2026 |
| | CVE-2024-35248 | Microsoft | high | 7.3 | 0.9%
| | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | Jun 11, 2024 | Jul 21, 2026 |
| | CVE-2024-30104 | Microsoft | high | 7.8 | 1.5%
| | Microsoft Office Remote Code Execution Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-30103 | Microsoft | high | 8.8 | 3.4%
| | Microsoft Outlook Remote Code Execution Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-30101 | Microsoft | high | 7.5 | 1.8%
| | Microsoft Office Remote Code Execution Vulnerability | Jun 11, 2024 | Jul 20, 2026 |
| | CVE-2024-30052 | Microsoft | medium | 4.7 | 1.4%
| | Visual Studio Remote Code Execution Vulnerability | Jun 11, 2024 | Jul 20, 2026 |