CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-9602

    Last Modified: 20 Nov 2025

    Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 8 Oct 2024
    8.4
    High

    CVE-2024-9412

    Last Modified: 15 Apr 2026

    An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.

    Published: 8 Oct 2024
    1.8
    Low

    CVE-2024-27457

    Last Modified: 15 Apr 2026

    Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 8 Oct 2024
    8.2
    High

    CVE-2024-47773

    Last Modified: 26 Aug 2025

    Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.

    Published: 8 Oct 2024
    3.1
    Low

    CVE-2024-47780

    Last Modified: 3 Sept 2025

    TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described. There are no known workarounds for this vulnerability.

    Published: 8 Oct 2024
    4.2
    Medium

    CVE-2024-47822

    Last Modified: 14 Apr 2025

    Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly sanitized or protected, an attacker with access to it can potentially gain administrative control, leading to unauthorized data access and manipulation. This impacts systems where the `LOG_STYLE` is set to `raw`. The `access_token` in the query could potentially be a long-lived static token. Users with impacted systems should rotate their static tokens if they were provided using query string. This vulnerability has been patched in release version 10.13.2 and subsequent releases as well. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Oct 2024
    7.7
    High

    CVE-2024-47823

    Last Modified: 17 Jul 2025

    Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension. If the following criteria are met, the attacker can carry out an RCE attack: 1. Filename is composed of the original file name using `$file->getClientOriginalName()`. 2. Files stored directly on your server in a public storage disk. 3. Webserver is configured to execute “.php” files. This issue has been addressed in release versions `2.12.7` and `3.5.2`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43488

    Last Modified: 9 Jun 2026

    Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43611

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    5.5
    Medium

    CVE-2024-43614

    Last Modified: 9 Jun 2026

    Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43583

    Last Modified: 9 Jun 2026

    Winlogon Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    5.5
    Medium

    CVE-2024-43603

    Last Modified: 9 Jun 2026

    Visual Studio Collector Service Denial of Service Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43599

    Last Modified: 9 Jun 2026

    Remote Desktop Client Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43593

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43592

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.7
    High

    CVE-2024-43591

    Last Modified: 8 Jul 2025

    Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43590

    Last Modified: 9 Jun 2026

    Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43589

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    5.5
    Medium

    CVE-2024-43585

    Last Modified: 9 Jun 2026

    Code Integrity Guard Security Feature Bypass Vulnerability

    Published: 8 Oct 2024
    7.7
    High

    CVE-2024-43584

    Last Modified: 9 Jun 2026

    Windows Scripting Engine Security Feature Bypass Vulnerability

    Published: 8 Oct 2024
    8.1
    High

    CVE-2024-43582

    Last Modified: 9 Jun 2026

    Remote Desktop Protocol Server Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43575

    Last Modified: 9 Jun 2026

    Windows Hyper-V Denial of Service Vulnerability

    Published: 8 Oct 2024
    8.3
    High

    CVE-2024-43574

    Last Modified: 9 Jun 2026

    Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43572

    Last Modified: 30 Oct 2025

    Microsoft Management Console Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    5.6
    Medium

    CVE-2024-43571

    Last Modified: 9 Jun 2026

    Sudo for Windows Spoofing Vulnerability

    Published: 8 Oct 2024
    6.4
    Medium

    CVE-2024-43570

    Last Modified: 9 Jun 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43567

    Last Modified: 9 Jun 2026

    Windows Hyper-V Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43565

    Last Modified: 9 Jun 2026

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43564

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43563

    Last Modified: 9 Jun 2026

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43562

    Last Modified: 9 Jun 2026

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43561

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43560

    Last Modified: 9 Jun 2026

    Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43559

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Denial of Service Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43558

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Denial of Service Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43557

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43556

    Last Modified: 9 Jun 2026

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43555

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.4
    High

    CVE-2024-43553

    Last Modified: 9 Jun 2026

    NT OS Kernel Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-43552

    Last Modified: 9 Jun 2026

    Windows Shell Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43551

    Last Modified: 9 Jun 2026

    Windows Storage Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.4
    High

    CVE-2024-43550

    Last Modified: 9 Jun 2026

    Windows Secure Channel Spoofing Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43549

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43547

    Last Modified: 9 Jun 2026

    Windows Kerberos Information Disclosure Vulnerability

    Published: 8 Oct 2024
    5.6
    Medium

    CVE-2024-43546

    Last Modified: 9 Jun 2026

    Windows Cryptographic Information Disclosure Vulnerability

    Published: 8 Oct 2024
    6.2
    Medium

    CVE-2024-35215

    Last Modified: 1 Dec 2025

    NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43545

    Last Modified: 9 Jun 2026

    Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43544

    Last Modified: 9 Jun 2026

    Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability

    Published: 8 Oct 2024
    6.8
    Medium

    CVE-2024-43536

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43528

    Last Modified: 9 Jun 2026

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

    Published: 8 Oct 2024