2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49551HIGH7.8Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2024-49535MEDIUM6.3Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-49534MEDIUM5.5Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-49533MEDIUM5.5Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-49532MEDIUM5.5Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-49531MEDIUM5.5Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-49530HIGH7.8Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by...
CVE-2024-46341HIGH8TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decod...
CVE-2024-46340CRITICAL9.8TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user cr...
CVE-2024-9844HIGH8.8Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows ...
CVE-2024-8540MEDIUM5.5Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker t...
CVE-2024-7572HIGH7.1Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitr...
CVE-2024-55550LOW2.7Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi...
CVE-2024-55500HIGH8.8Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls,...
CVE-2024-54008HIGH7.2An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vu...
CVE-2024-50931MEDIUM4.6Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
CVE-2024-50930HIGH8.8An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
CVE-2024-50929MEDIUM6.2Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change th...
CVE-2024-50928MEDIUM6.5Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup int...
CVE-2024-50924MEDIUM6.5Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communi...
CVE-2024-50921MEDIUM6.5Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Ser...
CVE-2024-50920HIGH8.8Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node vi...
CVE-2024-50699HIGH8TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak def...
CVE-2024-46442CRITICAL9.8An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attac...
CVE-2024-11773HIGH7.2SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with ad...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now