2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21975HIGH7.8Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le...
CVE-2024-21974HIGH7.8Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le...
CVE-2024-21958HIGH7.3Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve ...
CVE-2024-21957HIGH7.3Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve pr...
CVE-2024-21949MEDIUM5.5Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po...
CVE-2024-21946HIGH7.3Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achiev...
CVE-2024-21945HIGH7.3Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to...
CVE-2024-21939HIGH7.3Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow ...
CVE-2024-21938HIGH7.8Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)...
CVE-2024-21937HIGH7.8Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc...
CVE-2024-11138CRITICAL9.8A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /d...
CVE-2024-9999MEDIUM6.5In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Tr...
CVE-2024-9843MEDIUM5.5A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia...
CVE-2024-9842LOW3.3Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea...
CVE-2024-8539HIGH7.1Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod...
CVE-2024-7571HIGH7.8Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the...
CVE-2024-52010HIGH8.6Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea...
CVE-2024-51750MEDIUM5Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f...
CVE-2024-51749LOW3.5Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.8...
CVE-2024-50336MEDIUM5.3matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl...
CVE-2024-49528HIGH7.8Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar...
CVE-2024-49527MEDIUM5.5Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl...
CVE-2024-49526HIGH7.8Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar...
CVE-2024-49521HIGH7.7Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could ...
CVE-2024-49514HIGH7.8Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now