CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-49537

    Last Modified: 18 Dec 2024

    After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49553

    Last Modified: 18 Dec 2024

    Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49554

    Last Modified: 18 Dec 2024

    Media Encoder versions 25.0, 24.6.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49552

    Last Modified: 18 Dec 2024

    Media Encoder versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49551

    Last Modified: 18 Dec 2024

    Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    8.4
    High

    CVE-2024-49105

    Last Modified: 9 Jun 2026

    Remote Desktop Client Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49532

    Last Modified: 6 Feb 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49534

    Last Modified: 6 Feb 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49531

    Last Modified: 21 Jan 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49533

    Last Modified: 6 Feb 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    6.3
    Medium

    CVE-2024-49535

    Last Modified: 23 Jan 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that allows an attacker to provide malicious XML input containing a reference to an external entity, potentially leading to unauthorized read access outside the Acrobat sandbox. Exploitation of this issue requires user interaction in that a victim must process a malicious XML document.

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49530

    Last Modified: 21 Jan 2025

    Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Dec 2024
    7.1
    High

    CVE-2024-7572

    Last Modified: 11 Jul 2025

    Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-8540

    Last Modified: 30 Jul 2025

    Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

    Published: 10 Dec 2024
    7.1
    High

    CVE-2024-9844

    Last Modified: 17 Jan 2025

    Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.

    Published: 10 Dec 2024
    7.2
    High

    CVE-2024-54008

    Last Modified: 15 Apr 2026

    An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.

    Published: 10 Dec 2024
    5.7
    Medium

    CVE-2024-53244

    Last Modified: 6 Mar 2025

    In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on “/en-US/app/search/report“ endpoint through “s“ parameter.<br>The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

    Published: 10 Dec 2024
    5.3
    Medium

    CVE-2024-53246

    Last Modified: 12 Jul 2025

    In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation.

    Published: 10 Dec 2024
    4.3
    Medium

    CVE-2024-53243

    Last Modified: 15 Apr 2026

    In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.

    Published: 10 Dec 2024
    3.1
    Low

    CVE-2024-53245

    Last Modified: 6 Mar 2025

    In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard.

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-53247

    Last Modified: 15 Apr 2026

    In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49138

    Last Modified: 28 Oct 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    8.1
    High

    CVE-2024-49128

    Last Modified: 9 Jun 2026

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

    Published: 10 Dec 2024
    8.1
    High

    CVE-2024-49127

    Last Modified: 9 Jun 2026

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    8.1
    High

    CVE-2024-49118

    Last Modified: 9 Jun 2026

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    8.1
    High

    CVE-2024-49116

    Last Modified: 9 Jun 2026

    Windows Remote Desktop Services Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49114

    Last Modified: 9 Jun 2026

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.5
    High

    CVE-2024-49113

    Last Modified: 9 Jun 2026

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

    Published: 10 Dec 2024
    9.8
    Critical

    CVE-2024-49112

    Last Modified: 9 Jun 2026

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-49110

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    6.6
    Medium

    CVE-2024-49109

    Last Modified: 9 Jun 2026

    Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7
    High

    CVE-2024-49095

    Last Modified: 9 Jun 2026

    Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49090

    Last Modified: 9 Jun 2026

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49088

    Last Modified: 9 Jun 2026

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-49083

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-49082

    Last Modified: 9 Jun 2026

    Windows File Explorer Information Disclosure Vulnerability

    Published: 10 Dec 2024
    6.6
    Medium

    CVE-2024-49081

    Last Modified: 9 Jun 2026

    Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    8.8
    High

    CVE-2024-49080

    Last Modified: 9 Jun 2026

    Windows IP Routing Management Snapin Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49079

    Last Modified: 9 Jun 2026

    Input Method Editor (IME) Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-49078

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    6.8
    Medium

    CVE-2024-49077

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49076

    Last Modified: 9 Jun 2026

    Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.5
    High

    CVE-2024-49075

    Last Modified: 9 Jun 2026

    Windows Remote Desktop Services Denial of Service Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49072

    Last Modified: 9 Jun 2026

    Windows Task Scheduler Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    5.5
    Medium

    CVE-2024-49065

    Last Modified: 9 Jun 2026

    Microsoft Office Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    8.4
    High

    CVE-2024-49063

    Last Modified: 13 May 2025

    Microsoft/Muzic Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    6.5
    Medium

    CVE-2024-49062

    Last Modified: 9 Jun 2026

    Microsoft SharePoint Information Disclosure Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-43600

    Last Modified: 9 Jun 2026

    Microsoft Office Elevation of Privilege Vulnerability

    Published: 10 Dec 2024
    7.8
    High

    CVE-2024-49142

    Last Modified: 9 Jun 2026

    Microsoft Access Remote Code Execution Vulnerability

    Published: 10 Dec 2024
    8.1
    High

    CVE-2024-49132

    Last Modified: 9 Jun 2026

    Windows Remote Desktop Services Remote Code Execution Vulnerability

    Published: 10 Dec 2024