2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13962HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2...
CVE-2024-13961HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o...
CVE-2024-13960HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi...
CVE-2024-13959HIGH7.8Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows...
CVE-2024-13944HIGH7.8Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2....
CVE-2024-13759HIGH7.8Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attack...
CVE-2024-12442CRITICAL9.8EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s...
CVE-2024-11861CRITICAL9.8EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
CVE-2024-11617CRITICAL9.8The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t...
CVE-2024-9448HIGH7.5On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged...
CVE-2024-8100HIGH8.7On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used ...
CVE-2024-12378CRITICAL9.1On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac...
CVE-2024-11186CRITICAL10On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ...
CVE-2024-13009HIGH7.2In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when in...
CVE-2024-6648HIGH7.5Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote u...
CVE-2024-13793HIGH7.3The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execut...
CVE-2024-55651MEDIUM5.4i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and...
CVE-2024-11953——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-47619HIGH7.5syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo....
CVE-2024-12120MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Count...
CVE-2024-12225CRITICAL9.1A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa...
CVE-2024-49847HIGH7.5Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
CVE-2024-49846CRITICAL9.1Memory corruption while decoding of OTA messages from T3448 IE.
CVE-2024-49845HIGH7.8Memory corruption during the FRS UDS generation process.
CVE-2024-49844HIGH7.8Memory corruption while triggering commands in the PlayReady Trusted application.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now