2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34732HIGH8.4In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could l...
CVE-2024-13484HIGH8.2A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all nam...
CVE-2024-11956HIGH7.2A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affect...
CVE-2024-11135HIGH7.5The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'...
CVE-2024-0150HIGH7.1NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before th...
CVE-2024-0146HIGH7.8NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory cor...
CVE-2024-0136HIGH8.4NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-0135HIGH7.6NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le...
CVE-2024-45340HIGH8.8Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server...
CVE-2024-45339HIGH7.1When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr...
CVE-2024-57549HIGH7.5CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a G...
CVE-2024-57547HIGH7.5Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a cra...
CVE-2024-57546HIGH7.5An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validat...
CVE-2024-57373HIGH8.1Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized ...
CVE-2024-56316HIGH7.5In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenti...
CVE-2024-54557HIGH7.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, ...
CVE-2024-54543HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPa...
CVE-2024-54537HIGH8.2This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14....
CVE-2024-54522HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2...
CVE-2024-54517HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2...
CVE-2024-54509HIGH7.8An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, ma...
CVE-2024-54499HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, m...
CVE-2024-54468HIGH8.2The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequ...
CVE-2024-12740HIGH7.8Vision related software from NI used a third-party library for image processing that exposes several vulnerabilities. T...
CVE-2024-57276HIGH7.3In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. Th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now