CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2024-43645

    Last Modified: 8 Jul 2025

    Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-43644

    Last Modified: 8 Jul 2025

    Windows Client-Side Caching Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    6.8
    Medium

    CVE-2024-43643

    Last Modified: 8 Jul 2025

    Windows USB Video Class System Driver Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    6.8
    Medium

    CVE-2024-43638

    Last Modified: 8 Jul 2025

    Windows USB Video Class System Driver Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    6.8
    Medium

    CVE-2024-43637

    Last Modified: 8 Jul 2025

    Windows USB Video Class System Driver Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    6.8
    Medium

    CVE-2024-43634

    Last Modified: 8 Jul 2025

    Windows USB Video Class System Driver Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    6.7
    Medium

    CVE-2024-43631

    Last Modified: 8 Jul 2025

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-43630

    Last Modified: 8 Jul 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-43628

    Last Modified: 8 Jul 2025

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-43627

    Last Modified: 8 Jul 2025

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-43626

    Last Modified: 8 Jul 2025

    Windows Telephony Service Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    8.1
    High

    CVE-2024-43625

    Last Modified: 8 Jul 2025

    Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-43623

    Last Modified: 8 Jul 2025

    Windows NT OS Kernel Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    9.9
    Critical

    CVE-2024-43602

    Last Modified: 8 Jul 2025

    Azure CycleCloud Remote Code Execution Vulnerability

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-43530

    Last Modified: 8 Jul 2025

    Windows Update Stack Elevation of Privilege Vulnerability

    Published: 12 Nov 2024
    5.1
    Medium

    CVE-2024-8068

    Last Modified: 24 Oct 2025

    Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-21976

    Last Modified: 15 Apr 2026

    Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-21975

    Last Modified: 15 Nov 2024

    Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-21974

    Last Modified: 15 Nov 2024

    Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21958

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21957

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-21949

    Last Modified: 15 Nov 2024

    Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21946

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21945

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21939

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21938

    Last Modified: 18 Dec 2024

    Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-21937

    Last Modified: 27 Nov 2024

    Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 12 Nov 2024
    7
    High

    CVE-2024-10945

    Last Modified: 15 Apr 2026

    A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installation.

    Published: 12 Nov 2024
    7.1
    High

    CVE-2024-10944

    Last Modified: 15 Apr 2026

    A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improper input validation resulting in the possibility of a malicious Updated Agent being deployed.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49514

    Last Modified: 18 Nov 2024

    Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    9.1
    Critical

    CVE-2024-10943

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.

    Published: 12 Nov 2024
    8.6
    High

    CVE-2024-10923

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octane Management: from 16.2.100 through 24.4.

    Published: 12 Nov 2024
    9.8
    Critical

    CVE-2024-49369

    Last Modified: 26 Nov 2025

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.

    Published: 12 Nov 2024
    7.7
    High

    CVE-2024-49521

    Last Modified: 18 Nov 2024

    Adobe Commerce versions 3.2.5 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to a security feature bypass. A low privileged attacker could exploit this vulnerability to send crafted requests from the vulnerable server to internal systems, which could result in the bypassing of security measures such as firewalls. Exploitation of this issue does not require user interaction.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-50336

    Last Modified: 15 Apr 2026

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver. Fixed in matrix-js-sdk 34.11.1.

    Published: 12 Nov 2024
    5
    Medium

    CVE-2024-51750

    Last Modified: 15 Apr 2026

    Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.

    Published: 12 Nov 2024
    3.5
    Low

    CVE-2024-51749

    Last Modified: 15 Apr 2026

    Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.

    Published: 12 Nov 2024
    6.5
    Medium

    CVE-2024-9999

    Last Modified: 15 Apr 2026

    In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

    Published: 12 Nov 2024
    5.3
    Medium

    CVE-2024-30133

    Last Modified: 30 Oct 2025

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

    Published: 12 Nov 2024
    5.5
    Medium

    CVE-2024-49527

    Last Modified: 18 Nov 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49528

    Last Modified: 18 Nov 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-49526

    Last Modified: 18 Nov 2024

    Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Nov 2024
    7.8
    High

    CVE-2024-7571

    Last Modified: 17 Jan 2025

    Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

    Published: 12 Nov 2024
    5
    Medium

    CVE-2024-9843

    Last Modified: 17 Jan 2025

    A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

    Published: 12 Nov 2024
    7.3
    High

    CVE-2024-9842

    Last Modified: 17 Jan 2025

    Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

    Published: 12 Nov 2024
    7.1
    High

    CVE-2024-8539

    Last Modified: 17 Jan 2025

    Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.

    Published: 12 Nov 2024
    4.3
    Medium

    CVE-2024-11117

    Last Modified: 2 Jan 2025

    Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 12 Nov 2024
    4.3
    Medium

    CVE-2024-11116

    Last Modified: 2 Jan 2025

    Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Nov 2024
    8.8
    High

    CVE-2024-11115

    Last Modified: 2 Jan 2025

    Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)

    Published: 12 Nov 2024
    8.3
    High

    CVE-2024-11114

    Last Modified: 2 Jan 2025

    Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 12 Nov 2024