2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51447 | MEDIUM | 6.9 | 0.4% | May 13, 2025 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login... |
| CVE-2024-51446 | MEDIUM | 5.4 | 0.3% | May 13, 2025 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file ... |
| CVE-2024-51445 | HIGH | 7.1 | 0.4% | May 13, 2025 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affec... |
| CVE-2024-51444 | HIGH | 7.1 | 0.4% | May 13, 2025 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The appli... |
| CVE-2024-23815 | HIGH | 8.7 | 0.5% | May 13, 2025 | A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is a... |
| CVE-2024-55466 | MEDIUM | 6.5 | 0.3% | May 12, 2025 | An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard ... |
| CVE-2024-4982 | MEDIUM | 6.5 | 0.7% | May 12, 2025 | A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted gi... |
| CVE-2024-4981 | HIGH | 7.1 | 0.3% | May 12, 2025 | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links... |
| CVE-2024-56524 | CRITICAL | 9.1 | 0.5% | May 12, 2025 | Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by add... |
| CVE-2024-56523 | CRITICAL | 9.1 | 0.5% | May 12, 2025 | Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by pla... |
| CVE-2024-8973 | HIGH | 7.5 | 0.3% | May 9, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior... |
| CVE-2024-9524 | HIGH | 7.8 | 0.2% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime V... |
| CVE-2024-13962 | HIGH | 7.8 | 0.2% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2... |
| CVE-2024-13961 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o... |
| CVE-2024-13960 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi... |
| CVE-2024-13959 | HIGH | 7.8 | 0.2% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows... |
| CVE-2024-13944 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.... |
| CVE-2024-13759 | HIGH | 7.8 | 0.2% | May 9, 2025 | Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attack... |
| CVE-2024-12442 | CRITICAL | 9.8 | 1.1% | May 9, 2025 | EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s... |
| CVE-2024-11861 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access. |
| CVE-2024-11617 | CRITICAL | 9.8 | 1.2% | May 9, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t... |
| CVE-2024-9448 | HIGH | 7.5 | 0.5% | May 8, 2025 | On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged... |
| CVE-2024-8100 | HIGH | 8.7 | 0.5% | May 8, 2025 | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used ... |
| CVE-2024-12378 | CRITICAL | 9.1 | 0.4% | May 8, 2025 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac... |
| CVE-2024-11186 | CRITICAL | 10 | 0.6% | May 8, 2025 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now