2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10555 | MEDIUM | 4.8 | 0.3% | Dec 20, 2024 | The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, ... |
| CVE-2024-21549 | HIGH | 8.6 | 0.6% | Dec 20, 2024 | Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL ... |
| CVE-2024-44298 | LOW | 3.3 | 0.2% | Dec 20, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44293 | MEDIUM | 5.5 | 0.1% | Dec 20, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44292 | MEDIUM | 5.5 | 0.2% | Dec 20, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-44231 | MEDIUM | 4.6 | 0.5% | Dec 20, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with phy... |
| CVE-2024-44223 | MEDIUM | 4.6 | 0.3% | Dec 20, 2024 | This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ... |
| CVE-2024-44211 | MEDIUM | 5.5 | 0.4% | Dec 20, 2024 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ... |
| CVE-2024-44195 | HIGH | 7.5 | 0.7% | Dec 20, 2024 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to r... |
| CVE-2024-11776 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruit... |
| CVE-2024-12678 | MEDIUM | 6.5 | 0.5% | Dec 20, 2024 | Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace thr... |
| CVE-2024-54538 | HIGH | 7.5 | 0.9% | Dec 20, 2024 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.... |
| CVE-2024-12832 | MEDIUM | 6.3 | 0.5% | Dec 20, 2024 | Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remo... |
| CVE-2024-12831 | HIGH | 7.8 | 0.2% | Dec 20, 2024 | Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local... |
| CVE-2024-12830 | HIGH | 7.3 | 1.0% | Dec 20, 2024 | Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2024-12829 | HIGH | 8.8 | 1.3% | Dec 20, 2024 | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-56327 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crat... |
| CVE-2024-54663 | HIGH | 7.5 | 0.6% | Dec 19, 2024 | An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl... |
| CVE-2024-54009 | MEDIUM | 4 | 0.2% | Dec 19, 2024 | Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be... |
| CVE-2024-12700 | HIGH | 8.8 | 0.6% | Dec 19, 2024 | There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up... |
| CVE-2024-54984 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this... |
| CVE-2024-54983 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message. |
| CVE-2024-54982 | — | — | 0.2% | Dec 19, 2024 | An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS ... |
| CVE-2024-2201 | MEDIUM | 4.7 | 8.6% | Dec 19, 2024 | A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fin... |
| CVE-2024-12729 | HIGH | 8.8 | 1.3% | Dec 19, 2024 | A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now