2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43634 | MEDIUM | 6.8 | 0.7% | Nov 12, 2024 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
| CVE-2024-43633 | MEDIUM | 6.5 | 0.6% | Nov 12, 2024 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2024-43451 | MEDIUM | 6.5 | 81.8% | Nov 12, 2024 | NTLM Hash Disclosure Spoofing Vulnerability |
| CVE-2024-43449 | MEDIUM | 6.8 | 0.7% | Nov 12, 2024 | Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
| CVE-2024-38264 | MEDIUM | 5.9 | 1.3% | Nov 12, 2024 | Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability |
| CVE-2024-38203 | MEDIUM | 5.5 | 0.7% | Nov 12, 2024 | Windows Package Library Manager Information Disclosure Vulnerability |
| CVE-2024-21949 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po... |
| CVE-2024-9999 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Tr... |
| CVE-2024-9843 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia... |
| CVE-2024-51750 | MEDIUM | 5 | 0.5% | Nov 12, 2024 | Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f... |
| CVE-2024-50336 | MEDIUM | 5.3 | 0.8% | Nov 12, 2024 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl... |
| CVE-2024-49527 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl... |
| CVE-2024-30133 | MEDIUM | 5.3 | 0.3% | Nov 12, 2024 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not suff... |
| CVE-2024-11004 | MEDIUM | 6.1 | 0.9% | Nov 12, 2024 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a... |
| CVE-2024-52296 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp... |
| CVE-2024-47909 | MEDIUM | 4.9 | 1.1% | Nov 12, 2024 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2... |
| CVE-2024-47905 | MEDIUM | 4.9 | 1.1% | Nov 12, 2024 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2... |
| CVE-2024-47535 | MEDIUM | 5.5 | 0.4% | Nov 12, 2024 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2024-10971 | MEDIUM | 4.3 | 0.5% | Nov 12, 2024 | Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth... |
| CVE-2024-51566 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The NVMe driver queue processing is vulernable to guest-induced infinite loops. |
| CVE-2024-51565 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The hda driver is vulnerable to a buffer over-read from a guest-controlled value. |
| CVE-2024-51563 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition. |
| CVE-2024-51562 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value. |
| CVE-2024-39281 | MEDIUM | 5.3 | 0.4% | Nov 12, 2024 | The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel... |
| CVE-2024-33660 | MEDIUM | 5.2 | 0.1% | Nov 12, 2024 | An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now