2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38524 | HIGH | 7.5 | 0.4% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa... |
| CVE-2024-34711 | HIGH | 8.2 | 0.3% | Jun 10, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne... |
| CVE-2024-29198 | HIGH | 8.2 | 1.9% | Jun 10, 2025 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss... |
| CVE-2024-13090 | HIGH | 7.3 | 0.1% | Jun 10, 2025 | A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure... |
| CVE-2024-13089 | HIGH | 7.5 | 1.0% | Jun 10, 2025 | An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut... |
| CVE-2024-13088 | HIGH | 7.8 | 0.2% | Jun 6, 2025 | An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t... |
| CVE-2024-31127 | HIGH | 7.3 | 0.1% | Jun 4, 2025 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t... |
| CVE-2024-54189 | HIGH | 7.8 | 0.3% | Jun 3, 2025 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b... |
| CVE-2024-52561 | HIGH | 7.8 | 0.2% | Jun 3, 2025 | A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b... |
| CVE-2024-36486 | HIGH | 7.8 | 0.3% | Jun 3, 2025 | A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto... |
| CVE-2024-53026 | HIGH | 8.2 | 0.3% | Jun 3, 2025 | Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call. |
| CVE-2024-53021 | HIGH | 8.2 | 0.2% | Jun 3, 2025 | Information disclosure may occur while processing goodbye RTCP packet from network. |
| CVE-2024-53020 | HIGH | 8.2 | 0.2% | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with invalid header extension from network. |
| CVE-2024-53019 | HIGH | 8.2 | 0.2% | Jun 3, 2025 | Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so... |
| CVE-2024-53010 | HIGH | 7.8 | 0.1% | Jun 3, 2025 | Memory corruption may occur while attaching VM when the HLOS retains access to VM. |
| CVE-2024-57459 | HIGH | 7.3 | 0.2% | Jun 2, 2025 | A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds ... |
| CVE-2024-54028 | HIGH | 7.8 | 0.3% | Jun 2, 2025 | An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra... |
| CVE-2024-52035 | HIGH | 7.8 | 0.3% | Jun 2, 2025 | An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. ... |
| CVE-2024-48877 | HIGH | 7.8 | 0.3% | Jun 2, 2025 | A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers... |
| CVE-2024-57783 | HIGH | 8.1 | 0.2% | Jun 2, 2025 | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu... |
| CVE-2024-12168 | HIGH | 7.8 | 0.1% | Jun 2, 2025 | Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used. |
| CVE-2024-11857 | HIGH | 8.5 | 0.2% | Jun 2, 2025 | Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat... |
| CVE-2024-13917 | HIGH | 8.3 | 0.2% | May 30, 2025 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati... |
| CVE-2024-12224 | HIGH | 8.8 | 0.2% | May 30, 2025 | Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create... |
| CVE-2024-54952 | HIGH | 7.5 | 0.5% | May 29, 2025 | MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now