2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-12300LOW3.7The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca...
CVE-2024-10043LOW3.1An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting...
CVE-2024-54493LOW3.3This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicator...
CVE-2024-54491LOW3.3The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be ...
CVE-2024-54485LOW2.4The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macO...
CVE-2024-44290LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18...
CVE-2024-44200LOW3.3This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18...
CVE-2024-11053LOW3.4When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used f...
CVE-2024-55655LOW2.7sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer tha...
CVE-2024-54133LOW2.3Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) v...
CVE-2024-52831LOW3.5Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-43755LOW3.5Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that cou...
CVE-2024-55550LOW2.7Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi...
CVE-2024-47577LOW2.7Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability....
CVE-2024-47576LOW3.3SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Win...
CVE-2024-12174LOW2.7An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at...
CVE-2024-12057LOW1.8User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a W...
CVE-2024-6219LOW3.8Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust...
CVE-2024-6156LOW3.8Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese...
CVE-2024-54140LOW2.1sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...
CVE-2024-54014LOW3.6Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyla...
CVE-2024-38829LOW3.7A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from ...
CVE-2024-12056LOW2.3The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacke...
CVE-2024-53502LOW3.8Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVE-2024-53921LOW2.8An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now