2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24198 | HIGH | 7.5 | 0.5% | Jun 6, 2024 | smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c. |
| CVE-2024-24195 | HIGH | 7.5 | 0.4% | Jun 6, 2024 | robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c. |
| CVE-2024-24194 | HIGH | 7.5 | 0.4% | Jun 6, 2024 | robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-p... |
| CVE-2024-24192 | CRITICAL | 9.1 | 0.4% | Jun 6, 2024 | robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-inser... |
| CVE-2024-22525 | MEDIUM | 5.5 | 0.2% | Jun 6, 2024 | dnspod-sr 0dfbd37 contains a SEGV. |
| CVE-2024-22524 | MEDIUM | 5.5 | 0.2% | Jun 6, 2024 | dnspod-sr 0dfbd37 is vulnerable to buffer overflow. |
| CVE-2024-36795 | MEDIUM | 4 | 0.3% | Jun 6, 2024 | Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories em... |
| CVE-2024-32752 | CRITICAL | 9.1 | 0.6% | Jun 6, 2024 | The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with I... |
| CVE-2024-22074 | CRITICAL | 9.8 | 0.4% | Jun 6, 2024 | Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.... |
| CVE-2024-5609 | — | — | — | Jun 6, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6966. Reason: This candidate is a r... |
| CVE-2024-5552 | HIGH | 7.5 | 0.6% | Jun 6, 2024 | kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expr... |
| CVE-2024-5550 | MEDIUM | 5.3 | 0.8% | Jun 6, 2024 | In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system pa... |
| CVE-2024-5480 | — | — | — | Jun 6, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5478 | MEDIUM | 6.1 | 0.3% | Jun 6, 2024 | A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of luna... |
| CVE-2024-5328 | CRITICAL | 9.3 | 0.4% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the e... |
| CVE-2024-5307 | LOW | 3.3 | 0.4% | Jun 6, 2024 | Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows r... |
| CVE-2024-5306 | HIGH | 7.8 | 0.4% | Jun 6, 2024 | Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2024-5305 | HIGH | 7.8 | 0.4% | Jun 6, 2024 | Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-5304 | HIGH | 7.8 | 0.4% | Jun 6, 2024 | Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-5278 | MEDIUM | 6.1 | 0.6% | Jun 6, 2024 | gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of ... |
| CVE-2024-5248 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in ... |
| CVE-2024-5225 | HIGH | 7.2 | 0.4% | Jun 6, 2024 | An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` en... |
| CVE-2024-5206 | MEDIUM | 4.7 | 0.2% | Jun 6, 2024 | A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to ... |
| CVE-2024-5187 | HIGH | 8.8 | 1.2% | Jun 6, 2024 | A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for a... |
| CVE-2024-5186 | HIGH | 7.2 | 0.3% | Jun 6, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now