2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0135 | HIGH | 7.6 | 1.1% | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le... |
| CVE-2024-45341 | MEDIUM | 6.1 | 0.5% | Jan 28, 2025 | A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl... |
| CVE-2024-45340 | HIGH | 8.8 | 0.7% | Jan 28, 2025 | Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server... |
| CVE-2024-45339 | HIGH | 7.1 | 0.3% | Jan 28, 2025 | When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr... |
| CVE-2024-45336 | MEDIUM | 6.1 | 0.6% | Jan 28, 2025 | The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ contai... |
| CVE-2024-22315 | MEDIUM | 6.5 | 0.2% | Jan 28, 2025 | IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker w... |
| CVE-2024-27263 | MEDIUM | 5.3 | 0.3% | Jan 28, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obt... |
| CVE-2024-12649 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow... |
| CVE-2024-12648 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2024-12647 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2024-28786 | MEDIUM | 6.5 | 0.2% | Jan 28, 2025 | IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be ... |
| CVE-2024-57549 | HIGH | 7.5 | 0.6% | Jan 27, 2025 | CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a G... |
| CVE-2024-57548 | CRITICAL | 9.1 | 0.5% | Jan 27, 2025 | CMSimple 5.16 allows the user to edit log.php file via print page. |
| CVE-2024-57547 | HIGH | 7.5 | 0.5% | Jan 27, 2025 | Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a cra... |
| CVE-2024-57546 | HIGH | 7.5 | 0.6% | Jan 27, 2025 | An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validat... |
| CVE-2024-57373 | HIGH | 8.1 | 0.4% | Jan 27, 2025 | Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized ... |
| CVE-2024-57052 | CRITICAL | 9.8 | 0.5% | Jan 27, 2025 | An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter i... |
| CVE-2024-56316 | HIGH | 7.5 | 0.5% | Jan 27, 2025 | In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenti... |
| CVE-2024-56178 | MEDIUM | 6.5 | 0.3% | Jan 27, 2025 | An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a ... |
| CVE-2024-54728 | MEDIUM | 6.5 | 0.3% | Jan 27, 2025 | Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access sys... |
| CVE-2024-48662 | MEDIUM | 6.1 | 0.3% | Jan 27, 2025 | Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbit... |
| CVE-2024-54557 | HIGH | 7.5 | 0.5% | Jan 27, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, ... |
| CVE-2024-54550 | MEDIUM | 4 | 0.2% | Jan 27, 2025 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18... |
| CVE-2024-54549 | MEDIUM | 5.5 | 0.2% | Jan 27, 2025 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An... |
| CVE-2024-54547 | MEDIUM | 5.5 | 0.2% | Jan 27, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Vent... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now