2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50928 | MEDIUM | 6.5 | 0.3% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup int... |
| CVE-2024-50924 | MEDIUM | 6.5 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communi... |
| CVE-2024-50921 | MEDIUM | 6.5 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Ser... |
| CVE-2024-50920 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node vi... |
| CVE-2024-50699 | HIGH | 8 | 0.4% | Dec 10, 2024 | TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak def... |
| CVE-2024-46442 | CRITICAL | 9.8 | 0.6% | Dec 10, 2024 | An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attac... |
| CVE-2024-11773 | HIGH | 7.2 | 23.6% | Dec 10, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with ad... |
| CVE-2024-11772 | HIGH | 7.2 | 7.7% | Dec 10, 2024 | Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker wit... |
| CVE-2024-11639 | CRITICAL | 9.8 | 4.8% | Dec 10, 2024 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to... |
| CVE-2024-11634 | HIGH | 7.2 | 1.8% | Dec 10, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allo... |
| CVE-2024-11633 | HIGH | 7.2 | 1.7% | Dec 10, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin pr... |
| CVE-2024-10256 | HIGH | 7.1 | 0.2% | Dec 10, 2024 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbi... |
| CVE-2024-53866 | CRITICAL | 9.8 | 0.9% | Dec 10, 2024 | The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one works... |
| CVE-2024-53247 | HIGH | 8.8 | 1.1% | Dec 10, 2024 | In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure ... |
| CVE-2024-53246 | HIGH | 7.5 | 0.3% | Dec 10, 2024 | In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2... |
| CVE-2024-53245 | MEDIUM | 4.3 | 0.3% | Dec 10, 2024 | In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low... |
| CVE-2024-53244 | MEDIUM | 5.7 | 0.5% | Dec 10, 2024 | In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2... |
| CVE-2024-53243 | MEDIUM | 4.3 | 0.3% | Dec 10, 2024 | In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk ... |
| CVE-2024-12286 | CRITICAL | 9.8 | 0.4% | Dec 10, 2024 | MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials. |
| CVE-2024-55602 | HIGH | 8.5 | 0.7% | Dec 10, 2024 | PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticate... |
| CVE-2024-55548 | HIGH | 7.5 | 0.5% | Dec 10, 2024 | Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: throu... |
| CVE-2024-55547 | CRITICAL | 9.8 | 16.9% | Dec 10, 2024 | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. |
| CVE-2024-55546 | MEDIUM | 5.4 | 0.3% | Dec 10, 2024 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ... |
| CVE-2024-55545 | MEDIUM | 6.1 | 0.3% | Dec 10, 2024 | Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420... |
| CVE-2024-46657 | MEDIUM | 5.5 | 0.3% | Dec 10, 2024 | Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. Thi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now