CVE Feed

    Dashboard / CVE

    2.3
    Low

    CVE-2024-35274

    Last Modified: 17 Jan 2025

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write administrative privileges to create non-arbitrary files on a chosen directory via crafted CLI requests.

    Published: 12 Nov 2024
    6.7
    Medium

    CVE-2024-32118

    Last Modified: 17 Jan 2025

    Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.

    Published: 12 Nov 2024
    5.1
    Medium

    CVE-2024-32116

    Last Modified: 21 Jan 2025

    Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.

    Published: 12 Nov 2024
    4.1
    Medium

    CVE-2023-44255

    Last Modified: 21 Jan 2025

    An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.

    Published: 12 Nov 2024
    5.4
    Medium

    CVE-2023-47543

    Last Modified: 2 Jan 2025

    An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.

    Published: 12 Nov 2024
    4.9
    Medium

    CVE-2024-32117

    Last Modified: 21 Jan 2025

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to read arbitrary files from the underlying system via crafted HTTP or HTTPs requests.

    Published: 12 Nov 2024
    7.5
    High

    CVE-2024-40592

    Last Modified: 14 Nov 2024

    An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-36507

    Last Modified: 14 Nov 2024

    A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.

    Published: 12 Nov 2024
    4.3
    Medium

    CVE-2024-33510

    Last Modified: 17 Jan 2025

    An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version 24.2.b SSL-VPN web user interface may allow a remote unauthenticated attacker to perform phishing attempts via crafted requests.

    Published: 12 Nov 2024
    4.2
    Medium

    CVE-2023-50176

    Last Modified: 24 Aug 2026

    A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

    Published: 12 Nov 2024
    7.5
    High

    CVE-2024-23666

    Last Modified: 21 Jan 2025

    A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14 allows attacker to improper access control via crafted requests.

    Published: 12 Nov 2024
    8.2
    High

    CVE-2024-36513

    Last Modified: 14 Nov 2024

    A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.

    Published: 12 Nov 2024
    7.2
    High

    CVE-2024-43613

    Last Modified: 8 Jul 2025

    Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    7.2
    High

    CVE-2024-49042

    Last Modified: 8 Jul 2025

    Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-45147

    Last Modified: 14 Nov 2024

    Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-47458

    Last Modified: 14 Nov 2024

    Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7
    High

    CVE-2024-7516

    Last Modified: 4 Feb 2025

    A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote operations initiated by a switch admin.

    Published: 12 Nov 2024
    5.8
    Medium

    CVE-2024-8535

    Last Modified: 25 Jul 2025

    Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-47443

    Last Modified: 16 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-47441

    Last Modified: 16 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-47445

    Last Modified: 14 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-47444

    Last Modified: 14 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-47442

    Last Modified: 16 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-47446

    Last Modified: 14 Nov 2024

    After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    8.4
    High

    CVE-2024-8534

    Last Modified: 25 Jul 2025

    Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-47449

    Last Modified: 14 Nov 2024

    Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    6.4
    Medium

    CVE-2024-51722

    Last Modified: 15 Apr 2026

    A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained control of code running under one of the system accounts listed in the configuration file to potentially issue privileged script commands.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-51721

    Last Modified: 15 Apr 2026

    A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege.

    Published: 12 Nov 2024
    4.8
    Medium

    CVE-2024-51720

    Last Modified: 15 Apr 2026

    An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.

    Published: 12 Nov 2024
    5.1
    Medium

    CVE-2024-8069

    Last Modified: 24 Oct 2025

    Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49051

    Last Modified: 8 Jul 2025

    Microsoft PC Manager Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49050

    Last Modified: 15 Jul 2025

    Visual Studio Code Python Extension Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.1
    High

    CVE-2024-49048

    Last Modified: 8 Jul 2025

    TorchGeo Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49039

    Last Modified: 28 Oct 2025

    Windows Task Scheduler Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    7.5
    High

    CVE-2024-49033

    Last Modified: 8 Jul 2025

    Microsoft Word Security Feature Bypass Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49032

    Last Modified: 8 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49031

    Last Modified: 8 Jul 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49030

    Last Modified: 8 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49029

    Last Modified: 8 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49028

    Last Modified: 8 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49027

    Last Modified: 8 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49026

    Last Modified: 8 Jul 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49021

    Last Modified: 8 Jul 2025

    Microsoft SQL Server Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49019

    Last Modified: 8 Jul 2025

    Active Directory Certificate Services Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49018

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49017

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49016

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49015

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49014

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-49013

    Last Modified: 8 Jul 2025

    SQL Server Native Client Remote Code Execution Vulnerability

    Published: 12 Nov 2024