2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21925 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading ... |
| CVE-2024-21924 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services h... |
| CVE-2024-0179 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overw... |
| CVE-2024-21966 | HIGH | 7.3 | 0.2% | Feb 11, 2025 | A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation,... |
| CVE-2024-12833 | MEDIUM | 6.1 | 0.8% | Feb 11, 2025 | Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows n... |
| CVE-2024-12551 | HIGH | 7.8 | 0.4% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12550 | HIGH | 7.8 | 0.3% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-12549 | HIGH | 7.8 | 0.3% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12548 | LOW | 3.3 | 0.3% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability a... |
| CVE-2024-12547 | HIGH | 8.8 | 0.8% | Feb 11, 2025 | Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili... |
| CVE-2024-52968 | HIGH | 8.4 | 0.2% | Feb 11, 2025 | An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to Ma... |
| CVE-2024-52966 | LOW | 2.3 | 0.2% | Feb 11, 2025 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attac... |
| CVE-2024-50569 | HIGH | 7.2 | 1.9% | Feb 11, 2025 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 ... |
| CVE-2024-50567 | HIGH | 7.2 | 2.3% | Feb 11, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0... |
| CVE-2024-40591 | HIGH | 7.2 | 0.6% | Feb 11, 2025 | An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ... |
| CVE-2024-40586 | MEDIUM | 6.7 | 0.2% | Feb 11, 2025 | An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio... |
| CVE-2024-40584 | HIGH | 7.2 | 1.9% | Feb 11, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-36508 | MEDIUM | 6 | 0.2% | Feb 11, 2025 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2024-35279 | HIGH | 8.1 | 0.9% | Feb 11, 2025 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ... |
| CVE-2024-33504 | HIGH | 7.7 | 0.3% | Feb 11, 2025 | A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.... |
| CVE-2024-27781 | CRITICAL | 9 | 22.0% | Feb 11, 2025 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2024-27780 | MEDIUM | 5.4 | 0.3% | Feb 11, 2025 | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i... |
| CVE-2024-12756 | MEDIUM | 6.1 | 0.3% | Feb 11, 2025 | An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of ... |
| CVE-2024-12755 | MEDIUM | 5.4 | 0.3% | Feb 11, 2025 | A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di... |
| CVE-2024-47908 | HIGH | 7.2 | 22.0% | Feb 11, 2025 | OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now