2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38283MEDIUM5.1Sensitive customer information is stored in the device without encryption.
CVE-2024-38282HIGH8.5Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes t...
CVE-2024-37630HIGH8.8D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attac...
CVE-2024-37029HIGH7.8Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to ...
CVE-2024-37022HIGH7.8Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipul...
CVE-2024-36760HIGH7.5A stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs ...
CVE-2024-38281CRITICAL9.8An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
CVE-2024-38280MEDIUM4.6An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard ...
CVE-2024-38279MEDIUM4.6The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentic...
CVE-2024-37280MEDIUM4.9A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field map...
CVE-2024-37279MEDIUM4.3A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule r...
CVE-2024-35326Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-35325Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-32504HIGH7.8An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-31956HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length...
CVE-2024-37877MEDIUM5.5UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occu...
CVE-2024-37307MEDIUM6.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 an...
CVE-2024-35328Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-29169HIGH8.1Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST A...
CVE-2024-22441CRITICAL9.8HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
CVE-2024-37306HIGH7.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting i...
CVE-2024-37164HIGH8.5Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allow...
CVE-2024-37131CRITICAL9.8SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A rem...
CVE-2024-29168HIGH8.8Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST ...
CVE-2024-28969MEDIUM4.3Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now