| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49095 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-49093 | Hig | 0.57 | 8.8 | 0.01 | Dec 12, 2024 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | ||
| CVE-2024-49091 | Hig | 0.47 | 7.2 | 0.02 | Dec 12, 2024 | Windows Domain Name Service Remote Code Execution Vulnerability | ||
| CVE-2024-49090 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49089 | Hig | 0.47 | 7.2 | 0.02 | Dec 12, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-49088 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49086 | Hig | 0.57 | 8.8 | 0.02 | Dec 12, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-49085 | Hig | 0.57 | 8.8 | 0.02 | Dec 12, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-49084 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-49080 | Hig | 0.57 | 8.8 | 0.02 | Dec 12, 2024 | Windows IP Routing Management Snapin Remote Code Execution Vulnerability | ||
| CVE-2024-49079 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Input Method Editor (IME) Remote Code Execution Vulnerability | ||
| CVE-2024-49076 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | ||
| CVE-2024-49075 | Hig | 0.49 | 7.5 | 0.03 | Dec 12, 2024 | Windows Remote Desktop Services Denial of Service Vulnerability | ||
| CVE-2024-49074 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49072 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability | ||
| CVE-2024-49070 | Hig | 0.48 | 7.4 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2024-49069 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49068 | Hig | 0.53 | 8.2 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2024-49063 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Microsoft/Muzic Remote Code Execution Vulnerability | ||
| CVE-2024-49059 | Hig | 0.46 | 7.0 | 0.00 | Dec 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2024-49057 | Hig | 0.53 | 8.1 | 0.02 | Dec 12, 2024 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | ||
| CVE-2024-47835 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer… | ||
| CVE-2024-47778 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds… | ||
| CVE-2024-47603 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The vulnerability occurs when the gst_caps_is_equal function is… | ||
| CVE-2024-47602 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This function does not properly check the validity of the… | ||
| CVE-2024-47601 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the… | ||
| CVE-2024-47599 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from… | ||
| CVE-2024-47596 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, seqh_size is read from the input file without proper validation. If seqh_size is… | ||
| CVE-2024-47546 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than… | ||
| CVE-2024-47545 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less… | ||
| CVE-2024-47544 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed in 1.24.10. | ||
| CVE-2024-47543 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function qtdemux_parse_node, the value of length is not well checked. So, if length is… | ||
| CVE-2024-47542 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is… | ||
| CVE-2024-47541 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha)… | ||
| CVE-2024-45404 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication… | ||
| CVE-2024-43600 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2024-43594 | Hig | 0.48 | 7.3 | 0.02 | Dec 12, 2024 | Microsoft System Center Elevation of Privilege Vulnerability | ||
| CVE-2024-37401 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2024 | An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service. | ||
| CVE-2024-37377 | Hig | 0.49 | 7.5 | 0.02 | Dec 12, 2024 | A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service. | ||
| CVE-2024-12484 | Hig | 0.48 | 7.3 | 0.01 | Dec 12, 2024 | A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit… | ||
| CVE-2024-12382 | Hig | 0.58 | 8.8 | 0.05 | Dec 12, 2024 | Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2024-12381 | Hig | 0.58 | 8.8 | 0.05 | Dec 12, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2024-11950 | Hig | 0.57 | 8.8 | 0.00 | Dec 12, 2024 | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in… | ||
| CVE-2024-11949 | Hig | 0.57 | 8.8 | 0.01 | Dec 12, 2024 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The… | ||
| CVE-2024-11947 | Hig | 0.57 | 8.8 | 0.01 | Dec 12, 2024 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The… | ||
| CVE-2024-11872 | Hig | 0.51 | 7.8 | 0.00 | Dec 12, 2024 | Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code… | ||
| CVE-2024-9845 | Hig | 0.51 | 7.8 | 0.00 | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation. | ||
| CVE-2024-8496 | Hig | 0.51 | 7.8 | 0.00 | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. | ||
| CVE-2024-48912 | Hig | 0.53 | 8.1 | 0.00 | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue. | ||
| CVE-2024-47761 | Hig | 0.47 | 7.2 | 0.01 | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue. |
- risk 0.46cvss 7.0epss 0.00
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.02
Windows Domain Name Service Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Input Method Editor (IME) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Remote Desktop Services Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Task Scheduler Elevation of Privilege Vulnerability
- risk 0.48cvss 7.4epss 0.02
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.55cvss 8.4epss 0.02
Microsoft/Muzic Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.02
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in gst_wavparse_adtl_chunk within gstwavparse.c. This vulnerability arises due to insufficient validation of the size parameter, which can exceed the bounds…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The vulnerability occurs when the gst_caps_is_equal function is…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This function does not properly check the validity of the…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, seqh_size is read from the input file without proper validation. If seqh_size is…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed in 1.24.10.
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function qtdemux_parse_node, the value of length is not well checked. So, if length is…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is…
- risk 0.49cvss 7.5epss 0.01
GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha)…
- risk 0.53cvss 8.1epss 0.01
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication…
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.02
Microsoft System Center Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.01
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
- risk 0.49cvss 7.5epss 0.02
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
- risk 0.48cvss 7.3epss 0.01
A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit…
- risk 0.58cvss 8.8epss 0.05
Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.58cvss 8.8epss 0.05
Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.00
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in…
- risk 0.57cvss 8.8epss 0.01
GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The…
- risk 0.57cvss 8.8epss 0.01
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is required to exploit this vulnerability. The…
- risk 0.51cvss 7.8epss 0.00
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code…
- risk 0.51cvss 7.8epss 0.00
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
- risk 0.51cvss 7.8epss 0.00
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
- risk 0.53cvss 8.1epss 0.00
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.
- risk 0.47cvss 7.2epss 0.01
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the sent notifications contents can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.