2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0135HIGH7.6NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-45341MEDIUM6.1A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl...
CVE-2024-45340HIGH8.8Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server...
CVE-2024-45339HIGH7.1When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr...
CVE-2024-45336MEDIUM6.1The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ contai...
CVE-2024-22315MEDIUM6.5IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker w...
CVE-2024-27263MEDIUM5.3IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obt...
CVE-2024-12649CRITICAL9.8Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow...
CVE-2024-12648CRITICAL9.8Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2024-12647CRITICAL9.8Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2024-28786MEDIUM6.5IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be ...
CVE-2024-57549HIGH7.5CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a G...
CVE-2024-57548CRITICAL9.1CMSimple 5.16 allows the user to edit log.php file via print page.
CVE-2024-57547HIGH7.5Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a cra...
CVE-2024-57546HIGH7.5An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validat...
CVE-2024-57373HIGH8.1Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized ...
CVE-2024-57052CRITICAL9.8An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter i...
CVE-2024-56316HIGH7.5In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenti...
CVE-2024-56178MEDIUM6.5An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a ...
CVE-2024-54728MEDIUM6.5Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access sys...
CVE-2024-48662MEDIUM6.1Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbit...
CVE-2024-54557HIGH7.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, ...
CVE-2024-54550MEDIUM4This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18...
CVE-2024-54549MEDIUM5.5This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An...
CVE-2024-54547MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Vent...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now