CVE-2024-9602
Last Modified: 20 Nov 2025Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVE-2024-9412
Last Modified: 15 Apr 2026An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.
CVE-2024-27457
Last Modified: 15 Apr 2026Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access.
CVE-2024-47773
Last Modified: 26 Aug 2025Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.
CVE-2024-47780
Last Modified: 3 Sept 2025TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described. There are no known workarounds for this vulnerability.
CVE-2024-47822
Last Modified: 14 Apr 2025Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly sanitized or protected, an attacker with access to it can potentially gain administrative control, leading to unauthorized data access and manipulation. This impacts systems where the `LOG_STYLE` is set to `raw`. The `access_token` in the query could potentially be a long-lived static token. Users with impacted systems should rotate their static tokens if they were provided using query string. This vulnerability has been patched in release version 10.13.2 and subsequent releases as well. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-47823
Last Modified: 17 Jul 2025Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension. If the following criteria are met, the attacker can carry out an RCE attack: 1. Filename is composed of the original file name using `$file->getClientOriginalName()`. 2. Files stored directly on your server in a public storage disk. 3. Webserver is configured to execute “.php” files. This issue has been addressed in release versions `2.12.7` and `3.5.2`. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-43488
Last Modified: 9 Jun 2026Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
CVE-2024-43611
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43614
Last Modified: 9 Jun 2026Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
CVE-2024-43583
Last Modified: 9 Jun 2026Winlogon Elevation of Privilege Vulnerability
CVE-2024-43603
Last Modified: 9 Jun 2026Visual Studio Collector Service Denial of Service Vulnerability
CVE-2024-43599
Last Modified: 9 Jun 2026Remote Desktop Client Remote Code Execution Vulnerability
CVE-2024-43593
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43592
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43591
Last Modified: 8 Jul 2025Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
CVE-2024-43590
Last Modified: 9 Jun 2026Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
CVE-2024-43589
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43585
Last Modified: 9 Jun 2026Code Integrity Guard Security Feature Bypass Vulnerability
CVE-2024-43584
Last Modified: 9 Jun 2026Windows Scripting Engine Security Feature Bypass Vulnerability
CVE-2024-43582
Last Modified: 9 Jun 2026Remote Desktop Protocol Server Remote Code Execution Vulnerability
CVE-2024-43575
Last Modified: 9 Jun 2026Windows Hyper-V Denial of Service Vulnerability
CVE-2024-43574
Last Modified: 9 Jun 2026Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVE-2024-43572
Last Modified: 30 Oct 2025Microsoft Management Console Remote Code Execution Vulnerability
CVE-2024-43571
Last Modified: 9 Jun 2026Sudo for Windows Spoofing Vulnerability
CVE-2024-43570
Last Modified: 9 Jun 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-43567
Last Modified: 9 Jun 2026Windows Hyper-V Denial of Service Vulnerability
CVE-2024-43565
Last Modified: 9 Jun 2026Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVE-2024-43564
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43563
Last Modified: 9 Jun 2026Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2024-43562
Last Modified: 9 Jun 2026Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVE-2024-43561
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-43560
Last Modified: 9 Jun 2026Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
CVE-2024-43559
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-43558
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-43557
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-43556
Last Modified: 9 Jun 2026Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-43555
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Denial of Service Vulnerability
CVE-2024-43553
Last Modified: 9 Jun 2026NT OS Kernel Elevation of Privilege Vulnerability
CVE-2024-43552
Last Modified: 9 Jun 2026Windows Shell Remote Code Execution Vulnerability
CVE-2024-43551
Last Modified: 9 Jun 2026Windows Storage Elevation of Privilege Vulnerability
CVE-2024-43550
Last Modified: 9 Jun 2026Windows Secure Channel Spoofing Vulnerability
CVE-2024-43549
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-43547
Last Modified: 9 Jun 2026Windows Kerberos Information Disclosure Vulnerability
CVE-2024-43546
Last Modified: 9 Jun 2026Windows Cryptographic Information Disclosure Vulnerability
CVE-2024-35215
Last Modified: 1 Dec 2025NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.
CVE-2024-43545
Last Modified: 9 Jun 2026Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVE-2024-43544
Last Modified: 9 Jun 2026Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
CVE-2024-43536
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-43528
Last Modified: 9 Jun 2026Windows Secure Kernel Mode Elevation of Privilege Vulnerability
