2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44293 | MEDIUM | 5.5 | 0.1% | Dec 20, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44292 | MEDIUM | 5.5 | 0.2% | Dec 20, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44231 | MEDIUM | 4.6 | 0.5% | Dec 20, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with phy... |
| CVE-2024-44223 | MEDIUM | 4.6 | 0.3% | Dec 20, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ... |
| CVE-2024-44211 | MEDIUM | 5.5 | 0.4% | Dec 20, 2024 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ... |
| CVE-2024-11776 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruit... |
| CVE-2024-12678 | MEDIUM | 6.5 | 0.5% | Dec 20, 2024 | Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace thr... |
| CVE-2024-12832 | MEDIUM | 6.3 | 0.5% | Dec 20, 2024 | Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remo... |
| CVE-2024-54009 | MEDIUM | 4 | 0.2% | Dec 19, 2024 | Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be... |
| CVE-2024-2201 | MEDIUM | 4.7 | 8.6% | Dec 19, 2024 | A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fin... |
| CVE-2024-7139 | MEDIUM | 6.5 | 0.3% | Dec 19, 2024 | Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow tr... |
| CVE-2024-7138 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed... |
| CVE-2024-7137 | MEDIUM | 6.5 | 0.3% | Dec 19, 2024 | The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet ... |
| CVE-2024-53991 | MEDIUM | 5.9 | 25.4% | Dec 19, 2024 | Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi... |
| CVE-2024-52794 | MEDIUM | 6.1 | 0.3% | Dec 19, 2024 | Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect... |
| CVE-2024-56159 | MEDIUM | 5.3 | 1.5% | Dec 19, 2024 | Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read... |
| CVE-2024-52897 | MEDIUM | 6.2 | 0.2% | Dec 19, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive infor... |
| CVE-2024-51471 | MEDIUM | 5.3 | 0.3% | Dec 19, 2024 | IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service... |
| CVE-2024-49336 | MEDIUM | 5.4 | 0.2% | Dec 19, 2024 | IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated... |
| CVE-2024-12793 | MEDIUM | 4.3 | 0.5% | Dec 19, 2024 | A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is ... |
| CVE-2024-52896 | MEDIUM | 6.2 | 0.3% | Dec 19, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive infor... |
| CVE-2024-12798 | MEDIUM | 5.9 | 0.4% | Dec 19, 2024 | ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 t... |
| CVE-2024-47093 | MEDIUM | 6.1 | 0.5% | Dec 19, 2024 | Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS |
| CVE-2024-9102 | MEDIUM | 5 | 0.4% | Dec 19, 2024 | phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LD... |
| CVE-2024-12783 | MEDIUM | 6.1 | 0.4% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affect... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now