2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2299 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper valida... |
| CVE-2024-2290 | HIGH | 7.2 | 0.9% | May 14, 2024 | The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1... |
| CVE-2024-2257 | CRITICAL | 9.1 | 1.0% | May 14, 2024 | This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to impro... |
| CVE-2024-29895 | CRITICAL | 10 | 94.4% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x ... |
| CVE-2024-29894 | MEDIUM | 4.7 | 0.9% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a res... |
| CVE-2024-29857 | HIGH | 7.5 | 1.1% | May 14, 2024 | An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2... |
| CVE-2024-29800 | HIGH | 8 | 0.5% | May 14, 2024 | Deserialization of Untrusted Data vulnerability in Timber Team & Contributors Timber.This issue affects Timber: from n/a... |
| CVE-2024-29513 | HIGH | 7.8 | 0.4% | May 14, 2024 | An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute... |
| CVE-2024-29212 | CRITICAL | 9.9 | 1.6% | May 14, 2024 | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication betwe... |
| CVE-2024-29166 | MEDIUM | 5.7 | 0.2% | May 14, 2024 | HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction poin... |
| CVE-2024-29165 | HIGH | 7.4 | 0.2% | May 14, 2024 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction... |
| CVE-2024-29164 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction... |
| CVE-2024-29163 | HIGH | 7.4 | 0.2% | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction poi... |
| CVE-2024-29162 | HIGH | 7.4 | 0.2% | May 14, 2024 | HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or poten... |
| CVE-2024-29161 | HIGH | 8.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instr... |
| CVE-2024-29160 | HIGH | 7.4 | 0.2% | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the ... |
| CVE-2024-29159 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instructio... |
| CVE-2024-29158 | HIGH | 7.4 | 0.2% | May 14, 2024 | HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction ... |
| CVE-2024-29157 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer... |
| CVE-2024-28866 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a re... |
| CVE-2024-28781 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0... |
| CVE-2024-28761 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A ... |
| CVE-2024-28760 | MEDIUM | 4.3 | 0.5% | May 14, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial... |
| CVE-2024-28759 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09. |
| CVE-2024-28285 | CRITICAL | 9.8 | 0.5% | May 14, 2024 | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now