2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13962 | HIGH | 7.8 | 0.2% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2... |
| CVE-2024-13961 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o... |
| CVE-2024-13960 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi... |
| CVE-2024-13959 | HIGH | 7.8 | 0.2% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows... |
| CVE-2024-13944 | HIGH | 7.8 | 0.1% | May 9, 2025 | Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.... |
| CVE-2024-13759 | HIGH | 7.8 | 0.2% | May 9, 2025 | Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attack... |
| CVE-2024-12442 | CRITICAL | 9.8 | 1.1% | May 9, 2025 | EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s... |
| CVE-2024-11861 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access. |
| CVE-2024-11617 | CRITICAL | 9.8 | 1.2% | May 9, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t... |
| CVE-2024-9448 | HIGH | 7.5 | 0.5% | May 8, 2025 | On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged... |
| CVE-2024-8100 | HIGH | 8.7 | 0.5% | May 8, 2025 | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used ... |
| CVE-2024-12378 | CRITICAL | 9.1 | 0.4% | May 8, 2025 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac... |
| CVE-2024-11186 | CRITICAL | 10 | 0.6% | May 8, 2025 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ... |
| CVE-2024-13009 | HIGH | 7.2 | 0.4% | May 8, 2025 | In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when in... |
| CVE-2024-6648 | HIGH | 7.5 | 0.6% | May 8, 2025 | Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote u... |
| CVE-2024-13793 | HIGH | 7.3 | 0.3% | May 8, 2025 | The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execut... |
| CVE-2024-55651 | MEDIUM | 5.4 | 0.2% | May 8, 2025 | i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and... |
| CVE-2024-11953 | — | — | — | May 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-47619 | HIGH | 7.5 | 0.3% | May 7, 2025 | syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.... |
| CVE-2024-12120 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Count... |
| CVE-2024-12225 | CRITICAL | 9.1 | 0.3% | May 6, 2025 | A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa... |
| CVE-2024-49847 | HIGH | 7.5 | 0.2% | May 6, 2025 | Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE. |
| CVE-2024-49846 | CRITICAL | 9.1 | 0.2% | May 6, 2025 | Memory corruption while decoding of OTA messages from T3448 IE. |
| CVE-2024-49845 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption during the FRS UDS generation process. |
| CVE-2024-49844 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now