2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44174 | MEDIUM | 5.5 | 0.2% | Oct 28, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An attacker may be able to view r... |
| CVE-2024-44159 | HIGH | 7.1 | 0.3% | Oct 28, 2024 | A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fi... |
| CVE-2024-44156 | HIGH | 7.1 | 0.2% | Oct 28, 2024 | A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fi... |
| CVE-2024-44155 | MEDIUM | 6.5 | 0.5% | Oct 28, 2024 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 1... |
| CVE-2024-44144 | MEDIUM | 5.5 | 0.3% | Oct 28, 2024 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS ... |
| CVE-2024-44137 | MEDIUM | 4.6 | 0.3% | Oct 28, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventur... |
| CVE-2024-44126 | HIGH | 7.8 | 0.3% | Oct 28, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, mac... |
| CVE-2024-44123 | LOW | 2.3 | 0.2% | Oct 28, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequo... |
| CVE-2024-44122 | HIGH | 8.8 | 0.3% | Oct 28, 2024 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS S... |
| CVE-2024-42011 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat. |
| CVE-2024-40867 | CRITICAL | 9.6 | 0.7% | Oct 28, 2024 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPa... |
| CVE-2024-40855 | MEDIUM | 5.5 | 0.2% | Oct 28, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventur... |
| CVE-2024-40853 | LOW | 3.3 | 0.2% | Oct 28, 2024 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18.... |
| CVE-2024-40851 | LOW | 2.4 | 0.2% | Oct 28, 2024 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 1... |
| CVE-2024-40792 | LOW | 3.3 | 0.1% | Oct 28, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app... |
| CVE-2024-27849 | LOW | 3.3 | 0.2% | Oct 28, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-50457 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50453 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusi... |
| CVE-2024-50436 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50435 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50434 | HIGH | 8.8 | 0.4% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49755 | LOW | 3.1 | 0.3% | Oct 28, 2024 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authenti... |
| CVE-2024-48826 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arb... |
| CVE-2024-48825 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute a... |
| CVE-2024-48465 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now