2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35274 | LOW | 2.3 | 0.2% | Nov 12, 2024 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2024-33510 | MEDIUM | 4.3 | 0.6% | Nov 12, 2024 | An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE... |
| CVE-2024-33505 | HIGH | 7.3 | 0.5% | Nov 12, 2024 | A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7... |
| CVE-2024-32118 | MEDIUM | 6.7 | 0.6% | Nov 12, 2024 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE... |
| CVE-2024-32117 | MEDIUM | 4.9 | 0.8% | Nov 12, 2024 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2024-32116 | MEDIUM | 6 | 0.2% | Nov 12, 2024 | Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and befor... |
| CVE-2024-31496 | MEDIUM | 6.7 | 0.2% | Nov 12, 2024 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.... |
| CVE-2024-26011 | CRITICAL | 9.8 | 0.6% | Nov 12, 2024 | A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4... |
| CVE-2024-23666 | HIGH | 8.8 | 2.7% | Nov 12, 2024 | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 t... |
| CVE-2024-8069 | HIGH | 8 | 14.7% | Nov 12, 2024 | Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attac... |
| CVE-2024-8068 | HIGH | 8 | 1.4% | Nov 12, 2024 | Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated u... |
| CVE-2024-51720 | MEDIUM | 4.8 | 0.3% | Nov 12, 2024 | An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5... |
| CVE-2024-49056 | HIGH | 8.8 | 1.0% | Nov 12, 2024 | Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privil... |
| CVE-2024-49051 | HIGH | 7.8 | 0.6% | Nov 12, 2024 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2024-49050 | HIGH | 8.8 | 1.2% | Nov 12, 2024 | Visual Studio Code Python Extension Remote Code Execution Vulnerability |
| CVE-2024-49049 | HIGH | 7.1 | 0.4% | Nov 12, 2024 | Visual Studio Code Remote Extension Elevation of Privilege Vulnerability |
| CVE-2024-49048 | HIGH | 8.1 | 1.2% | Nov 12, 2024 | TorchGeo Remote Code Execution Vulnerability |
| CVE-2024-49046 | HIGH | 7.8 | 0.4% | Nov 12, 2024 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE-2024-49044 | MEDIUM | 6.7 | 0.7% | Nov 12, 2024 | Visual Studio Elevation of Privilege Vulnerability |
| CVE-2024-49043 | HIGH | 7.8 | 0.6% | Nov 12, 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability |
| CVE-2024-49040 | HIGH | 7.5 | 7.7% | Nov 12, 2024 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2024-49039 | HIGH | 8.8 | 13.7% | Nov 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability |
| CVE-2024-49033 | HIGH | 7.5 | 2.1% | Nov 12, 2024 | Microsoft Word Security Feature Bypass Vulnerability |
| CVE-2024-49032 | HIGH | 7.8 | 0.8% | Nov 12, 2024 | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2024-49031 | HIGH | 7.8 | 0.7% | Nov 12, 2024 | Microsoft Office Graphics Remote Code Execution Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now