2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4278 | LOW | 2.7 | 0.2% | Sep 26, 2024 | An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2... |
| CVE-2024-0133 | LOW | 3.4 | 0.2% | Sep 26, 2024 | NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a speciall... |
| CVE-2024-8350 | LOW | 2.7 | 0.4% | Sep 25, 2024 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check ... |
| CVE-2024-45599 | LOW | 3.8 | 0.2% | Sep 25, 2024 | Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access ... |
| CVE-2024-8263 | LOW | 2.7 | 0.4% | Sep 23, 2024 | An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PA... |
| CVE-2024-45453 | LOW | 3.7 | 0.3% | Sep 23, 2024 | Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This i... |
| CVE-2024-8612 | LOW | 3.8 | 0.2% | Sep 20, 2024 | A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set ... |
| CVE-2024-46794 | LOW | 3.3 | 0.2% | Sep 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_rea... |
| CVE-2024-46792 | LOW | 3.3 | 0.2% | Sep 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: riscv: misaligned: Restrict user access to kernel m... |
| CVE-2024-44180 | LOW | 2.4 | 0.2% | Sep 17, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc... |
| CVE-2024-44139 | LOW | 2.4 | 0.2% | Sep 17, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc... |
| CVE-2024-40838 | LOW | 3.3 | 0.2% | Sep 17, 2024 | A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.... |
| CVE-2024-40830 | LOW | 3.3 | 0.2% | Sep 17, 2024 | This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able ... |
| CVE-2024-40791 | LOW | 3.3 | 0.2% | Sep 17, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and ... |
| CVE-2024-36066 | LOW | 3.1 | 0.2% | Sep 12, 2024 | The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the securit... |
| CVE-2024-6446 | LOW | 3.5 | 0.4% | Sep 12, 2024 | An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.... |
| CVE-2024-44575 | LOW | 3.7 | 0.3% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could caus... |
| CVE-2024-1656 | LOW | 2.6 | 0.2% | Sep 11, 2024 | Affected versions of Octopus Server had a weak content security policy. |
| CVE-2024-45323 | LOW | 2.7 | 0.4% | Sep 10, 2024 | An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may all... |
| CVE-2024-36511 | LOW | 3.7 | 0.4% | Sep 10, 2024 | An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF)... |
| CVE-2024-8443 | LOW | 2.9 | 0.3% | Sep 10, 2024 | A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card... |
| CVE-2024-45284 | LOW | 2.4 | 0.2% | Sep 10, 2024 | An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricte... |
| CVE-2024-41728 | LOW | 2.7 | 0.3% | Sep 10, 2024 | Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logge... |
| CVE-2024-44114 | LOW | 2.7 | 0.2% | Sep 10, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that r... |
| CVE-2024-8042 | LOW | 3.1 | 0.2% | Sep 9, 2024 | Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now