2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33850 | MEDIUM | 4.3 | 0.2% | Jun 10, 2024 | Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster... |
| CVE-2024-27885 | MEDIUM | 6.3 | 0.3% | Jun 10, 2024 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonom... |
| CVE-2024-27850 | MEDIUM | 6.5 | 0.7% | Jun 10, 2024 | This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.... |
| CVE-2024-27844 | MEDIUM | 5.5 | 0.6% | Jun 10, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A web... |
| CVE-2024-27840 | MEDIUM | 6.3 | 0.3% | Jun 10, 2024 | The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and... |
| CVE-2024-27838 | MEDIUM | 6.5 | 0.7% | Jun 10, 2024 | The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iO... |
| CVE-2024-27830 | MEDIUM | 6.5 | 0.7% | Jun 10, 2024 | This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5... |
| CVE-2024-27812 | MEDIUM | 6.5 | 1.1% | Jun 10, 2024 | A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may... |
| CVE-2024-27807 | MEDIUM | 4.3 | 0.5% | Jun 10, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1... |
| CVE-2024-27806 | MEDIUM | 5.5 | 0.3% | Jun 10, 2024 | This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iO... |
| CVE-2024-27805 | MEDIUM | 5.5 | 0.3% | Jun 10, 2024 | An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 1... |
| CVE-2024-27800 | MEDIUM | 6.5 | 0.6% | Jun 10, 2024 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 ... |
| CVE-2024-23282 | MEDIUM | 5.5 | 0.2% | Jun 10, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1... |
| CVE-2024-23251 | MEDIUM | 4.6 | 0.4% | Jun 10, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.... |
| CVE-2024-36414 | MEDIUM | 6.5 | 0.4% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6... |
| CVE-2024-36413 | MEDIUM | 5.4 | 0.3% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6... |
| CVE-2024-27792 | MEDIUM | 5.5 | 0.2% | Jun 10, 2024 | This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An a... |
| CVE-2024-31612 | MEDIUM | 6.5 | 0.2% | Jun 10, 2024 | Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerabili... |
| CVE-2024-3850 | MEDIUM | 5.4 | 0.9% | Jun 10, 2024 | Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL... |
| CVE-2024-36407 | MEDIUM | 6.5 | 0.3% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ... |
| CVE-2024-35754 | MEDIUM | 6.5 | 0.5% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer ... |
| CVE-2024-35749 | MEDIUM | 5.3 | 0.3% | Jun 10, 2024 | Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authe... |
| CVE-2024-35747 | MEDIUM | 5.3 | 0.4% | Jun 10, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget... |
| CVE-2024-35744 | MEDIUM | 6.5 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upun... |
| CVE-2024-35743 | MEDIUM | 6.5 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Siteclean SC filechecker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now