2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10307 | MEDIUM | 5.5 | 0.2% | Mar 28, 2025 | An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17... |
| CVE-2024-49601 | CRITICAL | 9.8 | 1.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-13939 | HIGH | 7.5 | 0.3% | Mar 28, 2025 | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the... |
| CVE-2024-49565 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49564 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49563 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-55070 | LOW | 3.1 | 0.2% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo... |
| CVE-2024-55073 | HIGH | 7.6 | 0.3% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ... |
| CVE-2024-55072 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ... |
| CVE-2024-12905 | HIGH | 7.5 | 2.2% | Mar 27, 2025 | An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ... |
| CVE-2024-58091 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/... |
| CVE-2024-58090 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts ar... |
| CVE-2024-56469 | MEDIUM | 6.3 | 0.2% | Mar 27, 2025 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 ... |
| CVE-2024-48944 | MEDIUM | 6.5 | 0.6% | Mar 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques... |
| CVE-2024-9773 | HIGH | 8 | 0.2% | Mar 27, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from... |
| CVE-2024-45361 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation... |
| CVE-2024-45356 | HIGH | 7.3 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45355 | MEDIUM | 5.5 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45354 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp... |
| CVE-2024-45353 | MEDIUM | 4.3 | 0.1% | Mar 27, 2025 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca... |
| CVE-2024-45352 | HIGH | 8.8 | 0.3% | Mar 27, 2025 | An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro... |
| CVE-2024-55965 | MEDIUM | 6.5 | 0.4% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in... |
| CVE-2024-55964 | CRITICAL | 9.8 | 6.3% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea... |
| CVE-2024-55963 | MEDIUM | 6.5 | 27.7% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ... |
| CVE-2024-41643 | MEDIUM | 6.8 | 0.3% | Mar 26, 2025 | An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now