2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10900 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-10899 | HIGH | 7.3 | 0.6% | Nov 20, 2024 | The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio... |
| CVE-2024-10855 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that... |
| CVE-2024-44308 | HIGH | 8.8 | 9.2% | Nov 20, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18... |
| CVE-2024-44307 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-44306 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-51669 | HIGH | 8.8 | 0.2% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Wi... |
| CVE-2024-52359 | HIGH | 8.8 | 0.3% | Nov 19, 2024 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions ... |
| CVE-2024-45422 | HIGH | 7.5 | 0.5% | Nov 19, 2024 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial o... |
| CVE-2024-45419 | HIGH | 7.5 | 0.5% | Nov 19, 2024 | Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via... |
| CVE-2024-11395 | HIGH | 8.8 | 0.4% | Nov 19, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-51503 | HIGH | 8.8 | 4.0% | Nov 19, 2024 | A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an at... |
| CVE-2024-21697 | HIGH | 8.8 | 0.7% | Nov 19, 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and ... |
| CVE-2024-53082 | HIGH | 7.1 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: Add hash_key_length check Add hash_key... |
| CVE-2024-53068 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix slab-use-after-free in scmi... |
| CVE-2024-53062 | HIGH | 7.1 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: mgb4: protect driver against spectre Freque... |
| CVE-2024-53061 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: s5p-jpeg: prevent buffer overflows The curr... |
| CVE-2024-53059 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix response handling in iwl_mv... |
| CVE-2024-53057 | HIGH | 7.8 | 0.3% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/sched: stop qdisc_tree_reduce_backlog on TC_H_R... |
| CVE-2024-48992 | HIGH | 7.8 | 6.6% | Nov 19, 2024 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric... |
| CVE-2024-48991 | HIGH | 7.8 | 5.3% | Nov 19, 2024 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winn... |
| CVE-2024-48990 | HIGH | 7.8 | 19.9% | Nov 19, 2024 | Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric... |
| CVE-2024-11003 | HIGH | 7.8 | 11.5% | Nov 19, 2024 | Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which e... |
| CVE-2024-10224 | HIGH | 7.8 | 8.6% | Nov 19, 2024 | Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local att... |
| CVE-2024-52789 | HIGH | 8 | 0.4% | Nov 19, 2024 | Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now