2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38283 | MEDIUM | 5.1 | 0.1% | Jun 13, 2024 | Sensitive customer information is stored in the device without encryption. |
| CVE-2024-38282 | HIGH | 8.5 | 0.2% | Jun 13, 2024 | Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes t... |
| CVE-2024-37630 | HIGH | 8.8 | 0.4% | Jun 13, 2024 | D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attac... |
| CVE-2024-37029 | HIGH | 7.8 | 0.3% | Jun 13, 2024 | Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to ... |
| CVE-2024-37022 | HIGH | 7.8 | 0.3% | Jun 13, 2024 | Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipul... |
| CVE-2024-36760 | HIGH | 7.5 | 0.4% | Jun 13, 2024 | A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs ... |
| CVE-2024-38281 | CRITICAL | 9.8 | 0.4% | Jun 13, 2024 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. |
| CVE-2024-38280 | MEDIUM | 4.6 | 0.2% | Jun 13, 2024 | An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard ... |
| CVE-2024-38279 | MEDIUM | 4.6 | 0.3% | Jun 13, 2024 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentic... |
| CVE-2024-37280 | MEDIUM | 4.9 | 0.5% | Jun 13, 2024 | A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field map... |
| CVE-2024-37279 | MEDIUM | 4.3 | 0.4% | Jun 13, 2024 | A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule r... |
| CVE-2024-35326 | — | — | — | Jun 13, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-35325 | — | — | — | Jun 13, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-32504 | HIGH | 7.8 | 0.2% | Jun 13, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ... |
| CVE-2024-31956 | HIGH | 7.8 | 0.2% | Jun 13, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length... |
| CVE-2024-37877 | MEDIUM | 5.5 | 0.3% | Jun 13, 2024 | UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occu... |
| CVE-2024-37307 | MEDIUM | 6.5 | 0.2% | Jun 13, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 an... |
| CVE-2024-35328 | — | — | — | Jun 13, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-29169 | HIGH | 8.1 | 0.4% | Jun 13, 2024 | Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST A... |
| CVE-2024-22441 | CRITICAL | 9.8 | 0.5% | Jun 13, 2024 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. |
| CVE-2024-37306 | HIGH | 7.1 | 0.2% | Jun 13, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting i... |
| CVE-2024-37164 | HIGH | 8.5 | 0.3% | Jun 13, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allow... |
| CVE-2024-37131 | CRITICAL | 9.8 | 0.5% | Jun 13, 2024 | SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A rem... |
| CVE-2024-29168 | HIGH | 8.8 | 0.5% | Jun 13, 2024 | Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST ... |
| CVE-2024-28969 | MEDIUM | 4.3 | 0.4% | Jun 13, 2024 | Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now