2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21945HIGH7.3Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to...
CVE-2024-21939HIGH7.3Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow ...
CVE-2024-21938HIGH7.8Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)...
CVE-2024-21937HIGH7.8Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc...
CVE-2024-8539HIGH7.1Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod...
CVE-2024-7571HIGH7.8Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the...
CVE-2024-52010HIGH8.6Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea...
CVE-2024-49528HIGH7.8Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2024-49526HIGH7.8Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar...
CVE-2024-49521HIGH7.7Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could ...
CVE-2024-49514HIGH7.8Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi...
CVE-2024-11006HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-11005HIGH7.2Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be...
CVE-2024-10945HIGH7.3A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privi...
CVE-2024-10944HIGH8.4A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss...
CVE-2024-10923HIGH8.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ A...
CVE-2024-9420HIGH8.8A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-8495HIGH7.5A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7...
CVE-2024-52297HIGH7.5Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon...
CVE-2024-50331HIGH7.5An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se...
CVE-2024-50329HIGH8.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-50328HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50327HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50326HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-50324HIGH7.2Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now