2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34470 | HIGH | 8.6 | 6.7% | May 6, 2024 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability ... |
| CVE-2024-34466 | — | — | — | May 6, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34467. Reason: This candidate is a reservation d... |
| CVE-2024-34252 | HIGH | 7.5 | 0.6% | May 6, 2024 | wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "Pres... |
| CVE-2024-34249 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "Deallo... |
| CVE-2024-34078 | MEDIUM | 6.1 | 0.6% | May 6, 2024 | html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), ... |
| CVE-2024-34069 | HIGH | 7.5 | 3.4% | May 6, 2024 | Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an att... |
| CVE-2024-34064 | MEDIUM | 5.4 | 1.0% | May 6, 2024 | Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non... |
| CVE-2024-33294 | CRITICAL | 9.1 | 0.7% | May 6, 2024 | An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via... |
| CVE-2024-33113 | MEDIUM | 5.3 | 3.4% | May 6, 2024 | D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php. |
| CVE-2024-33112 | HIGH | 7.5 | 6.5% | May 6, 2024 | D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func. |
| CVE-2024-33111 | MEDIUM | 5.4 | 0.8% | May 6, 2024 | D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php. |
| CVE-2024-33110 | CRITICAL | 9.1 | 0.7% | May 6, 2024 | D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component. |
| CVE-2024-32982 | HIGH | 8.2 | 0.7% | May 6, 2024 | Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a ... |
| CVE-2024-32972 | HIGH | 7.5 | 0.8% | May 6, 2024 | go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable n... |
| CVE-2024-23354 | HIGH | 7.8 | 0.2% | May 6, 2024 | Memory corruption when the IOCTL call is interrupted by a signal. |
| CVE-2024-23351 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. |
| CVE-2024-21480 | CRITICAL | 9.8 | 0.3% | May 6, 2024 | Memory corruption while playing audio file having large-sized input buffer. |
| CVE-2024-21477 | HIGH | 7.5 | 0.3% | May 6, 2024 | Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. |
| CVE-2024-21476 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when the channel ID passed by user is not validated and further used. |
| CVE-2024-21475 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| CVE-2024-21474 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when size of buffer from previous call is used without validation or re-initialization. |
| CVE-2024-21471 | HIGH | 7.8 | 0.1% | May 6, 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. |
| CVE-2024-4549 | HIGH | 7.5 | 1.1% | May 6, 2024 | A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS... |
| CVE-2024-4548 | CRITICAL | 9.8 | 29.4% | May 6, 2024 | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalcula... |
| CVE-2024-4547 | CRITICAL | 9.8 | 1.9% | May 6, 2024 | A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalculat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now