CVE-2024-43645
Last Modified: 8 Jul 2025Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability
CVE-2024-43644
Last Modified: 8 Jul 2025Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2024-43643
Last Modified: 8 Jul 2025Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43638
Last Modified: 8 Jul 2025Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43637
Last Modified: 8 Jul 2025Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43634
Last Modified: 8 Jul 2025Windows USB Video Class System Driver Elevation of Privilege Vulnerability
CVE-2024-43631
Last Modified: 8 Jul 2025Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2024-43630
Last Modified: 8 Jul 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-43628
Last Modified: 8 Jul 2025Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43627
Last Modified: 8 Jul 2025Windows Telephony Service Remote Code Execution Vulnerability
CVE-2024-43626
Last Modified: 8 Jul 2025Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2024-43625
Last Modified: 8 Jul 2025Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
CVE-2024-43623
Last Modified: 8 Jul 2025Windows NT OS Kernel Elevation of Privilege Vulnerability
CVE-2024-43602
Last Modified: 8 Jul 2025Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-43530
Last Modified: 8 Jul 2025Windows Update Stack Elevation of Privilege Vulnerability
CVE-2024-8068
Last Modified: 24 Oct 2025Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
CVE-2024-21976
Last Modified: 15 Apr 2026Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21975
Last Modified: 15 Nov 2024Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21974
Last Modified: 15 Nov 2024Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21958
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2024-21957
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21949
Last Modified: 15 Nov 2024Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
CVE-2024-21946
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21945
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21939
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21938
Last Modified: 18 Dec 2024Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2024-21937
Last Modified: 27 Nov 2024Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-10945
Last Modified: 15 Apr 2026A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installation.
CVE-2024-10944
Last Modified: 15 Apr 2026A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improper input validation resulting in the possibility of a malicious Updated Agent being deployed.
CVE-2024-49514
Last Modified: 18 Nov 2024Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-10943
Last Modified: 15 Apr 2026An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.
CVE-2024-10923
Last Modified: 15 Apr 2026Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octane Management: from 16.2.100 through 24.4.
CVE-2024-49369
Last Modified: 26 Nov 2025Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.
CVE-2024-49521
Last Modified: 18 Nov 2024Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.
CVE-2024-50336
Last Modified: 15 Apr 2026matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver. Fixed in matrix-js-sdk 34.11.1.
CVE-2024-51750
Last Modified: 15 Apr 2026Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
CVE-2024-51749
Last Modified: 15 Apr 2026Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.
CVE-2024-9999
Last Modified: 15 Apr 2026In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
CVE-2024-30133
Last Modified: 30 Oct 2025HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
CVE-2024-49527
Last Modified: 18 Nov 2024Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-49528
Last Modified: 18 Nov 2024Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-49526
Last Modified: 18 Nov 2024Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-7571
Last Modified: 17 Jan 2025Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
CVE-2024-9843
Last Modified: 17 Jan 2025A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-9842
Last Modified: 17 Jan 2025Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
CVE-2024-8539
Last Modified: 17 Jan 2025Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-11117
Last Modified: 2 Jan 2025Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-11116
Last Modified: 2 Jan 2025Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-11115
Last Modified: 2 Jan 2025Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)
CVE-2024-11114
Last Modified: 2 Jan 2025Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
