2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49545 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c... |
| CVE-2024-49544 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds write vulnerability that could r... |
| CVE-2024-49543 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that ... |
| CVE-2024-49538 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2024-49537 | HIGH | 7.8 | 0.5% | Dec 10, 2024 | After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could... |
| CVE-2024-49513 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitra... |
| CVE-2024-45156 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result i... |
| CVE-2024-45155 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could ... |
| CVE-2024-51165 | HIGH | 7.5 | 0.6% | Dec 10, 2024 | SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow... |
| CVE-2024-49553 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2024-49552 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | Media Encoder versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could re... |
| CVE-2024-49551 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2024-49530 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-46341 | HIGH | 8 | 0.2% | Dec 10, 2024 | TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decod... |
| CVE-2024-9844 | HIGH | 8.8 | 1.0% | Dec 10, 2024 | Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows ... |
| CVE-2024-7572 | HIGH | 7.1 | 0.2% | Dec 10, 2024 | Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitr... |
| CVE-2024-55500 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls,... |
| CVE-2024-54008 | HIGH | 7.2 | 0.8% | Dec 10, 2024 | An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vu... |
| CVE-2024-50930 | HIGH | 8.8 | 0.3% | Dec 10, 2024 | An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code. |
| CVE-2024-50920 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node vi... |
| CVE-2024-50699 | HIGH | 8 | 0.4% | Dec 10, 2024 | TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak def... |
| CVE-2024-11773 | HIGH | 7.2 | 23.6% | Dec 10, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with ad... |
| CVE-2024-11772 | HIGH | 7.2 | 7.7% | Dec 10, 2024 | Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker wit... |
| CVE-2024-11634 | HIGH | 7.2 | 1.8% | Dec 10, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allo... |
| CVE-2024-11633 | HIGH | 7.2 | 1.7% | Dec 10, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now