2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21945 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to... |
| CVE-2024-21939 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow ... |
| CVE-2024-21938 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)... |
| CVE-2024-21937 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc... |
| CVE-2024-8539 | HIGH | 7.1 | 0.2% | Nov 12, 2024 | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod... |
| CVE-2024-7571 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the... |
| CVE-2024-52010 | HIGH | 8.6 | 1.4% | Nov 12, 2024 | Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea... |
| CVE-2024-49528 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-49526 | HIGH | 7.8 | 0.4% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar... |
| CVE-2024-49521 | HIGH | 7.7 | 0.7% | Nov 12, 2024 | Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could ... |
| CVE-2024-49514 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi... |
| CVE-2024-11006 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-11005 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-10945 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privi... |
| CVE-2024-10944 | HIGH | 8.4 | 0.5% | Nov 12, 2024 | A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss... |
| CVE-2024-10923 | HIGH | 8.6 | 0.3% | Nov 12, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ A... |
| CVE-2024-9420 | HIGH | 8.8 | 1.4% | Nov 12, 2024 | A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-8495 | HIGH | 7.5 | 1.3% | Nov 12, 2024 | A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7... |
| CVE-2024-52297 | HIGH | 7.5 | 0.6% | Nov 12, 2024 | Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon... |
| CVE-2024-50331 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se... |
| CVE-2024-50329 | HIGH | 8.8 | 1.7% | Nov 12, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-50328 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50327 | HIGH | 7.2 | 1.0% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50326 | HIGH | 7.2 | 25.8% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50324 | HIGH | 7.2 | 18.2% | Nov 12, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now