| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8534 | Hig | 0.53 | 8.1 | 0.01 | Nov 12, 2024 | Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy… | ||
| CVE-2024-7516 | Hig | 0.46 | 7.1 | 0.00 | Nov 12, 2024 | A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote… | ||
| CVE-2024-51721 | Hig | 0.47 | 7.3 | 0.00 | Nov 12, 2024 | A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege. | ||
| CVE-2024-49042 | Hig | 0.47 | 7.2 | 0.01 | Nov 12, 2024 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-47452 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47451 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47450 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-47443 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-47442 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-47441 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-45114 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2024-43613 | Hig | 0.47 | 7.2 | 0.01 | Nov 12, 2024 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-40592 | Hig | 0.49 | 7.5 | 0.00 | Nov 12, 2024 | An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package… | ||
| CVE-2024-36513 | Hig | 0.53 | 8.2 | 0.00 | Nov 12, 2024 | A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts. | ||
| CVE-2024-36507 | Hig | 0.47 | 7.3 | 0.00 | Nov 12, 2024 | A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering. | ||
| CVE-2024-23666 | Hig | 0.49 | 7.5 | 0.03 | Nov 12, 2024 | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through… | ||
| CVE-2023-50176 | Hig | 0.49 | 7.5 | 0.01 | Nov 12, 2024 | A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link. | ||
| CVE-2024-8069 | Hig | 0.65 | 8.0 | 0.15 | KEV | Nov 12, 2024 | Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server | |
| CVE-2024-8068 | Hig | 0.64 | 8.0 | 0.01 | KEV | Nov 12, 2024 | Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain | |
| CVE-2024-49056 | Hig | 0.48 | 7.3 | 0.01 | Nov 12, 2024 | Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-49051 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft PC Manager Elevation of Privilege Vulnerability | ||
| CVE-2024-49050 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | ||
| CVE-2024-49049 | Hig | 0.46 | 7.1 | 0.00 | Nov 12, 2024 | Visual Studio Code Remote Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-49048 | Hig | 0.46 | 8.1 | 0.01 | Nov 12, 2024 | TorchGeo Remote Code Execution Vulnerability | ||
| CVE-2024-49046 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2024 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | ||
| CVE-2024-49043 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | ||
| CVE-2024-49040 | Hig | 0.49 | 7.5 | 0.08 | Nov 12, 2024 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2024-49039 | Hig | 0.76 | 8.8 | 0.14 | KEV | Nov 12, 2024 | Windows Task Scheduler Elevation of Privilege Vulnerability | |
| CVE-2024-49033 | Hig | 0.49 | 7.5 | 0.02 | Nov 12, 2024 | Microsoft Word Security Feature Bypass Vulnerability | ||
| CVE-2024-49032 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2024-49031 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2024-49030 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49029 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49028 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49027 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49026 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-49021 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-49019 | Hig | 0.51 | 7.8 | 0.02 | Nov 12, 2024 | Active Directory Certificate Services Elevation of Privilege Vulnerability | ||
| CVE-2024-49018 | Hig | 0.57 | 8.8 | 0.02 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49017 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49016 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49015 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49014 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49013 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49012 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49011 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49010 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49009 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49008 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49007 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
- risk 0.53cvss 8.1epss 0.01
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy…
- risk 0.46cvss 7.1epss 0.00
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Service Session Hijacking that may arise from the attacker's ability to forge an SSH key while the Brocade Fabric OS Switch is performing various remote…
- risk 0.47cvss 7.3epss 0.00
A code injection vulnerability in the SecuSUITE Server Web Administration Portal of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially inject script commands or other executable content into the server that would run with root privilege.
- risk 0.47cvss 7.2epss 0.01
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 28.7.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.47cvss 7.2epss 0.01
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.00
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package…
- risk 0.53cvss 8.2epss 0.00
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
- risk 0.47cvss 7.3epss 0.00
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
- risk 0.49cvss 7.5epss 0.03
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through…
- risk 0.49cvss 7.5epss 0.01
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
- risk 0.65cvss 8.0epss 0.15
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
- risk 0.64cvss 8.0epss 0.01
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
- risk 0.48cvss 7.3epss 0.01
Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.01
Microsoft PC Manager Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Visual Studio Code Python Extension Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.00
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
- risk 0.46cvss 8.1epss 0.01
TorchGeo Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.08
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.76cvss 8.8epss 0.14
Windows Task Scheduler Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Word Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Active Directory Certificate Services Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability