2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10555MEDIUM4.8The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, ...
CVE-2024-21549HIGH8.6Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL ...
CVE-2024-44298LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-44293MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-44292MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-44231MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with phy...
CVE-2024-44223MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ...
CVE-2024-44211MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ...
CVE-2024-44195HIGH7.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to r...
CVE-2024-11776MEDIUM6.4The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruit...
CVE-2024-12678MEDIUM6.5Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace thr...
CVE-2024-54538HIGH7.5A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17....
CVE-2024-12832MEDIUM6.3Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remo...
CVE-2024-12831HIGH7.8Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local...
CVE-2024-12830HIGH7.3Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2024-12829HIGH8.8Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-56327CRITICAL9.8pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crat...
CVE-2024-54663HIGH7.5An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl...
CVE-2024-54009MEDIUM4Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be...
CVE-2024-12700HIGH8.8There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up...
CVE-2024-54984CRITICAL9.8An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this...
CVE-2024-54983CRITICAL9.8An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
CVE-2024-54982An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS ...
CVE-2024-2201MEDIUM4.7A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fin...
CVE-2024-12729HIGH8.8A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now