2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44270 | HIGH | 8.6 | 0.7% | Oct 28, 2024 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, ma... |
| CVE-2024-44259 | HIGH | 7.5 | 1.0% | Oct 28, 2024 | This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17... |
| CVE-2024-44258 | HIGH | 7.1 | 0.8% | Oct 28, 2024 | This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18... |
| CVE-2024-44255 | HIGH | 7.8 | 0.3% | Oct 28, 2024 | A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ... |
| CVE-2024-44252 | HIGH | 7.1 | 0.3% | Oct 28, 2024 | A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 a... |
| CVE-2024-44228 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inhe... |
| CVE-2024-44218 | HIGH | 7.8 | 0.3% | Oct 28, 2024 | This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS ... |
| CVE-2024-44208 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. An app may be able ... |
| CVE-2024-44203 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be a... |
| CVE-2024-44159 | HIGH | 7.1 | 0.3% | Oct 28, 2024 | A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fi... |
| CVE-2024-44156 | HIGH | 7.1 | 0.2% | Oct 28, 2024 | A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fi... |
| CVE-2024-44126 | HIGH | 7.8 | 0.3% | Oct 28, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, mac... |
| CVE-2024-44122 | HIGH | 8.8 | 0.3% | Oct 28, 2024 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS S... |
| CVE-2024-42011 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat. |
| CVE-2024-50457 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50453 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusi... |
| CVE-2024-50436 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50435 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50434 | HIGH | 8.8 | 0.4% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-48826 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arb... |
| CVE-2024-48825 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute a... |
| CVE-2024-48196 | HIGH | 7.5 | 0.5% | Oct 28, 2024 | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post pa... |
| CVE-2024-48178 | HIGH | 8.1 | 0.3% | Oct 28, 2024 | newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter. |
| CVE-2024-6245 | HIGH | 7.4 | 0.2% | Oct 28, 2024 | Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker ... |
| CVE-2024-42028 | HIGH | 8.8 | 0.2% | Oct 28, 2024 | A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (V... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now