2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37055HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling...
CVE-2024-37054HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling ...
CVE-2024-37053HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ...
CVE-2024-37052HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ...
CVE-2024-5463MEDIUM6.5A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in t...
CVE-2024-4637MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2024-5000HIGH7.5An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS produ...
CVE-2024-4581MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widge...
CVE-2024-5422HIGH7.1An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnse...
CVE-2024-5421HIGH8.7Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-int...
CVE-2024-5420HIGH8.3Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec...
CVE-2024-4253CRITICAL9.1A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.y...
CVE-2024-36104CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue...
CVE-2024-5485MEDIUM6.4The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to St...
CVE-2024-20887HIGH7.5Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary ...
CVE-2024-20886MEDIUM6.2Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary d...
CVE-2024-20885LOW3.3Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to ...
CVE-2024-20884HIGH7.8Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Re...
CVE-2024-20883HIGH7.8Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-20...
CVE-2024-20882MEDIUM4.6Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary d...
CVE-2024-20881MEDIUM6.7Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers...
CVE-2024-20880MEDIUM6.8Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to ove...
CVE-2024-20879HIGH7.1Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write...
CVE-2024-20878HIGH7.8Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows loc...
CVE-2024-20877HIGH7.8Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now