2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21975 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le... |
| CVE-2024-21974 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially le... |
| CVE-2024-21958 | HIGH | 7.3 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve ... |
| CVE-2024-21957 | HIGH | 7.3 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve pr... |
| CVE-2024-21949 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, po... |
| CVE-2024-21946 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achiev... |
| CVE-2024-21945 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to... |
| CVE-2024-21939 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow ... |
| CVE-2024-21938 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)... |
| CVE-2024-21937 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc... |
| CVE-2024-11138 | CRITICAL | 9.8 | 2.5% | Nov 12, 2024 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /d... |
| CVE-2024-9999 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Tr... |
| CVE-2024-9843 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denia... |
| CVE-2024-9842 | LOW | 3.3 | 0.2% | Nov 12, 2024 | Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea... |
| CVE-2024-8539 | HIGH | 7.1 | 0.2% | Nov 12, 2024 | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod... |
| CVE-2024-7571 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the... |
| CVE-2024-52010 | HIGH | 8.6 | 1.4% | Nov 12, 2024 | Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea... |
| CVE-2024-51750 | MEDIUM | 5 | 0.5% | Nov 12, 2024 | Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over f... |
| CVE-2024-51749 | LOW | 3.5 | 0.3% | Nov 12, 2024 | Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.8... |
| CVE-2024-50336 | MEDIUM | 5.3 | 0.8% | Nov 12, 2024 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl... |
| CVE-2024-49528 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar... |
| CVE-2024-49527 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl... |
| CVE-2024-49526 | HIGH | 7.8 | 0.4% | Nov 12, 2024 | Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar... |
| CVE-2024-49521 | HIGH | 7.7 | 0.7% | Nov 12, 2024 | Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could ... |
| CVE-2024-49514 | HIGH | 7.8 | 0.3% | Nov 12, 2024 | Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now