2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50318 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o... |
| CVE-2024-50317 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial o... |
| CVE-2024-47909 | MEDIUM | 4.9 | 1.1% | Nov 12, 2024 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2... |
| CVE-2024-47907 | HIGH | 7.5 | 1.5% | Nov 12, 2024 | A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated ... |
| CVE-2024-47906 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy... |
| CVE-2024-47905 | MEDIUM | 4.9 | 1.1% | Nov 12, 2024 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 2... |
| CVE-2024-47535 | MEDIUM | 5.5 | 0.4% | Nov 12, 2024 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2024-43415 | CRITICAL | 9 | 0.7% | Nov 12, 2024 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_aw... |
| CVE-2024-11007 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-10971 | MEDIUM | 4.3 | 0.5% | Nov 12, 2024 | Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth... |
| CVE-2024-8074 | CRITICAL | 9.3 | 0.4% | Nov 12, 2024 | Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows... |
| CVE-2024-51566 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The NVMe driver queue processing is vulernable to guest-induced infinite loops. |
| CVE-2024-51565 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The hda driver is vulnerable to a buffer over-read from a guest-controlled value. |
| CVE-2024-51564 | HIGH | 7.5 | 0.4% | Nov 12, 2024 | A guest can trigger an infinite loop in the hda audio driver. |
| CVE-2024-51563 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition. |
| CVE-2024-51562 | MEDIUM | 6.5 | 0.4% | Nov 12, 2024 | The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value. |
| CVE-2024-50386 | CRITICAL | 9.9 | 1.4% | Nov 12, 2024 | Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary... |
| CVE-2024-45289 | HIGH | 7.5 | 0.3% | Nov 12, 2024 | The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname.... |
| CVE-2024-42442 | HIGH | 8.8 | 0.8% | Nov 12, 2024 | APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations wit... |
| CVE-2024-39281 | MEDIUM | 5.3 | 0.4% | Nov 12, 2024 | The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel... |
| CVE-2024-37365 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects wi... |
| CVE-2024-33660 | MEDIUM | 5.2 | 0.1% | Nov 12, 2024 | An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. |
| CVE-2024-33658 | HIGH | 7.8 | 0.2% | Nov 12, 2024 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bou... |
| CVE-2024-2315 | HIGH | 7.1 | 0.1% | Nov 12, 2024 | APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploita... |
| CVE-2024-11130 | MEDIUM | 4.8 | 0.3% | Nov 12, 2024 | A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now