2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43462 | HIGH | 8.8 | 1.6% | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-43459 | HIGH | 8.8 | 1.6% | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-43452 | HIGH | 7.5 | 24.3% | Nov 12, 2024 | Windows Registry Elevation of Privilege Vulnerability |
| CVE-2024-43450 | HIGH | 7.5 | 0.6% | Nov 12, 2024 | Windows DNS Spoofing Vulnerability |
| CVE-2024-43447 | HIGH | 8.1 | 1.4% | Nov 12, 2024 | Windows SMBv3 Server Remote Code Execution Vulnerability |
| CVE-2024-38255 | HIGH | 8.8 | 1.6% | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-21976 | HIGH | 8.8 | 0.3% | Nov 12, 2024 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le... |
| CVE-2024-21975 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le... |
| CVE-2024-21974 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le... |
| CVE-2024-21958 | HIGH | 7.3 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve ... |
| CVE-2024-21957 | HIGH | 7.3 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve pr... |
| CVE-2024-21946 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achiev... |
| CVE-2024-21945 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to... |
| CVE-2024-21939 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow ... |
| CVE-2024-21938 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)... |
| CVE-2024-21937 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc... |
| CVE-2024-8539 | HIGH | 7.1 | 0.2% | Nov 12, 2024 | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod... |
| CVE-2024-7571 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the... |
| CVE-2024-52010 | HIGH | 8.6 | 1.4% | Nov 12, 2024 | Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea... |
| CVE-2024-49528 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-49526 | HIGH | 7.8 | 0.4% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar... |
| CVE-2024-49521 | HIGH | 7.7 | 0.7% | Nov 12, 2024 | Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could ... |
| CVE-2024-49514 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi... |
| CVE-2024-11006 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-11005 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now