2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50618MEDIUM4.3A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all...
CVE-2024-26480HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p...
CVE-2024-26479MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command...
CVE-2024-26478MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us...
CVE-2024-26477HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par...
CVE-2024-36324HIGH8.8Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia...
CVE-2024-36320HIGH7Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to ...
CVE-2024-36316MEDIUM5.5The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially ...
CVE-2024-56808HIGH7.8A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network...
CVE-2024-56807MEDIUM5.5An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo...
CVE-2024-36355HIGH7Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec...
CVE-2024-36311MEDIUM4.6A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t...
CVE-2024-36310MEDIUM4.6Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds...
CVE-2024-21953MEDIUM5.9Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o...
CVE-2024-54192MEDIUM5.5An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g...
CVE-2024-52334MEDIUM6.3A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ...
CVE-2024-51451MEDIUM6.5IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO...
CVE-2024-43181MEDIUM6.3IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe...
CVE-2024-40685MEDIUM4.3IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are...
CVE-2024-39724MEDIUM5.3IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper...
CVE-2024-5986CRITICAL9.1A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve...
CVE-2024-5386HIGH8.8In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ...
CVE-2024-4147MEDIUM6.5In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p...
CVE-2024-2356CRITICAL9.6A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap...
CVE-2024-54263HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now