2024 CVE Vulnerabilities

No CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-51481LOW1Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, expo...
CVE-2024-10228LOW3.3The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified...
CVE-2024-10452LOW2.7Organization admins can delete pending invites created in an organization they are not part of.
CVE-2024-41156LOW2.7Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide po...
CVE-2024-44265LOW2.4The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, ma...
CVE-2024-44251LOW2.4This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker...
CVE-2024-44222LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, ma...
CVE-2024-44123LOW2.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequo...
CVE-2024-40853LOW3.3This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18....
CVE-2024-40851LOW2.4This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 1...
CVE-2024-40792LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app...
CVE-2024-27849LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-49755LOW3.1Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authenti...
CVE-2024-5532LOW1.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ O...
CVE-2024-10214LOW3.5Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the ...
CVE-2024-8013LOW3.3A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in express...
CVE-2024-23843LOW2.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC...
CVE-2024-50610LOW3.6GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When ...
CVE-2024-47821LOW2.3pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain ...
CVE-2024-10372LOW2A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function...
CVE-2024-49751LOW1.2Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2024-49208LOW3.1Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supportin...
CVE-2024-48926LOW3.1Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions...
CVE-2024-43173LOW3.7IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-50057LOW3.3In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Free IRQ only if it was requested...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now