2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25036 | LOW | 3.3 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security all... |
| CVE-2024-49417 | LOW | 3.3 | 0.1% | Dec 3, 2024 | Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch... |
| CVE-2024-49414 | LOW | 2.4 | 0.2% | Dec 3, 2024 | Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to t... |
| CVE-2024-11856 | LOW | 3.7 | 0.3% | Dec 2, 2024 | A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification. |
| CVE-2024-52800 | LOW | 2.3 | 1.1% | Nov 29, 2024 | veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI in... |
| CVE-2024-53701 | LOW | 3.1 | 0.2% | Nov 29, 2024 | Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications... |
| CVE-2024-46939 | LOW | 2.4 | 0.2% | Nov 28, 2024 | The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameter... |
| CVE-2024-36464 | LOW | 2.7 | 0.5% | Nov 27, 2024 | When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type... |
| CVE-2024-42333 | LOW | 2.7 | 0.6% | Nov 27, 2024 | The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read... |
| CVE-2024-42332 | LOW | 3.7 | 0.6% | Nov 27, 2024 | The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with addit... |
| CVE-2024-42331 | LOW | 3.3 | 0.3% | Nov 27, 2024 | In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript... |
| CVE-2024-42329 | LOW | 3.3 | 0.2% | Nov 27, 2024 | The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function... |
| CVE-2024-22117 | LOW | 2.2 | 0.5% | Nov 26, 2024 | When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s... |
| CVE-2024-8160 | LOW | 2.7 | 0.6% | Nov 26, 2024 | Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficie... |
| CVE-2024-10492 | LOW | 2.7 | 0.7% | Nov 25, 2024 | A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file th... |
| CVE-2024-7056 | LOW | 3.5 | 0.5% | Nov 25, 2024 | The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2024-10710 | LOW | 3.5 | 0.4% | Nov 25, 2024 | The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-9763 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9762 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabil... |
| CVE-2024-9761 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9760 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9759 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9757 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9754 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-9753 | LOW | 3.3 | 0.3% | Nov 22, 2024 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now