2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54009 | MEDIUM | 4 | 0.2% | Dec 19, 2024 | Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be... |
| CVE-2024-12700 | HIGH | 8.8 | 0.6% | Dec 19, 2024 | There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up... |
| CVE-2024-54984 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this... |
| CVE-2024-54983 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message. |
| CVE-2024-54982 | — | — | 0.2% | Dec 19, 2024 | An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS ... |
| CVE-2024-2201 | MEDIUM | 4.7 | 8.6% | Dec 19, 2024 | A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fin... |
| CVE-2024-12729 | HIGH | 8.8 | 1.3% | Dec 19, 2024 | A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho... |
| CVE-2024-12728 | CRITICAL | 9.8 | 0.9% | Dec 19, 2024 | A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than versi... |
| CVE-2024-12727 | CRITICAL | 9.8 | 1.4% | Dec 19, 2024 | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (... |
| CVE-2024-12672 | HIGH | 7.3 | 0.2% | Dec 19, 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the... |
| CVE-2024-12175 | HIGH | 7.8 | 0.3% | Dec 19, 2024 | Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat... |
| CVE-2024-11364 | HIGH | 7.3 | 0.3% | Dec 19, 2024 | Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow ... |
| CVE-2024-11157 | HIGH | 7.3 | 0.2% | Dec 19, 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the... |
| CVE-2024-7139 | MEDIUM | 6.5 | 0.3% | Dec 19, 2024 | Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow tr... |
| CVE-2024-7138 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed... |
| CVE-2024-7137 | MEDIUM | 6.5 | 0.3% | Dec 19, 2024 | The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet ... |
| CVE-2024-53991 | MEDIUM | 5.9 | 25.4% | Dec 19, 2024 | Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi... |
| CVE-2024-52794 | MEDIUM | 6.1 | 0.3% | Dec 19, 2024 | Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect... |
| CVE-2024-52589 | LOW | 2.7 | 0.2% | Dec 19, 2024 | Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin ... |
| CVE-2024-49765 | CRITICAL | 9.1 | 0.4% | Dec 19, 2024 | Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc... |
| CVE-2024-12111 | HIGH | 8 | 0.4% | Dec 19, 2024 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac... |
| CVE-2024-56200 | HIGH | 8.6 | 0.6% | Dec 19, 2024 | Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr... |
| CVE-2024-56159 | MEDIUM | 5.3 | 1.5% | Dec 19, 2024 | Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read... |
| CVE-2024-55196 | HIGH | 7.5 | 0.4% | Dec 19, 2024 | Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl... |
| CVE-2024-54150 | CRITICAL | 9.1 | 0.4% | Dec 19, 2024 | cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now