2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49551 | HIGH | 7.8 | 0.3% | Dec 10, 2024 | Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2024-49535 | MEDIUM | 6.3 | 0.4% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-49534 | MEDIUM | 5.5 | 0.5% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-49533 | MEDIUM | 5.5 | 0.5% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-49532 | MEDIUM | 5.5 | 0.5% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-49531 | MEDIUM | 5.5 | 0.3% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-49530 | HIGH | 7.8 | 0.4% | Dec 10, 2024 | Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by... |
| CVE-2024-46341 | HIGH | 8 | 0.2% | Dec 10, 2024 | TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decod... |
| CVE-2024-46340 | CRITICAL | 9.8 | 0.3% | Dec 10, 2024 | TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user cr... |
| CVE-2024-9844 | HIGH | 8.8 | 1.0% | Dec 10, 2024 | Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows ... |
| CVE-2024-8540 | MEDIUM | 5.5 | 0.2% | Dec 10, 2024 | Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker t... |
| CVE-2024-7572 | HIGH | 7.1 | 0.2% | Dec 10, 2024 | Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitr... |
| CVE-2024-55550 | LOW | 2.7 | 38.1% | Dec 10, 2024 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi... |
| CVE-2024-55500 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls,... |
| CVE-2024-54008 | HIGH | 7.2 | 0.8% | Dec 10, 2024 | An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vu... |
| CVE-2024-50931 | MEDIUM | 4.6 | 0.2% | Dec 10, 2024 | Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions. |
| CVE-2024-50930 | HIGH | 8.8 | 0.3% | Dec 10, 2024 | An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code. |
| CVE-2024-50929 | MEDIUM | 6.2 | 0.2% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change th... |
| CVE-2024-50928 | MEDIUM | 6.5 | 0.3% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup int... |
| CVE-2024-50924 | MEDIUM | 6.5 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communi... |
| CVE-2024-50921 | MEDIUM | 6.5 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Ser... |
| CVE-2024-50920 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node vi... |
| CVE-2024-50699 | HIGH | 8 | 0.4% | Dec 10, 2024 | TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak def... |
| CVE-2024-46442 | CRITICAL | 9.8 | 0.6% | Dec 10, 2024 | An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attac... |
| CVE-2024-11773 | HIGH | 7.2 | 23.6% | Dec 10, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with ad... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now