2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27879HIGH7.5The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS ...
CVE-2024-27876MEDIUM5.5A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS...
CVE-2024-27875MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators ...
CVE-2024-27874HIGH7.5This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attack...
CVE-2024-27869MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may ...
CVE-2024-27861MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be ab...
CVE-2024-27860MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be ab...
CVE-2024-27858MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be a...
CVE-2024-27795HIGH7.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extens...
CVE-2024-23237MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to ca...
CVE-2024-6685MEDIUM4.3An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5,...
CVE-2024-4283MEDIUM6.1An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, a...
CVE-2024-45416HIGH8.1The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session ...
CVE-2024-45415CRITICAL9.8The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity functio...
CVE-2024-45414CRITICAL9.8The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. ...
CVE-2024-45413HIGH8.1The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This f...
CVE-2024-8766MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2024-45800MEDIUM5Snappymail is an open source web-based email client. SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS ...
CVE-2024-44445Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-42798HIGH7.6An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_us...
CVE-2024-42796MEDIUM5.9An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management...
CVE-2024-42795MEDIUM4.2An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_use...
CVE-2024-42794MEDIUM4.7Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
CVE-2024-34016MEDIUM6.5Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2024-22013MEDIUM5.3U-Boot environment is read from unauthenticated partition.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now