2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25943 | CRITICAL | 9.8 | 0.7% | Jun 29, 2024 | iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a sessi... |
| CVE-2024-6265 | CRITICAL | 9.8 | 2.4% | Jun 29, 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ... |
| CVE-2024-37371 | CRITICAL | 9.1 | 1.9% | Jun 28, 2024 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling... |
| CVE-2024-5827 | CRITICAL | 9.8 | 3.5% | Jun 28, 2024 | Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can injec... |
| CVE-2024-38371 | CRITICAL | 9.8 | 0.6% | Jun 28, 2024 | authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin... |
| CVE-2024-6403 | CRITICAL | 9.8 | 1.0% | Jun 28, 2024 | A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is t... |
| CVE-2024-6402 | CRITICAL | 9.8 | 1.0% | Jun 28, 2024 | A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the functi... |
| CVE-2024-3816 | CRITICAL | 9.8 | 0.5% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar... |
| CVE-2024-39704 | CRITICAL | 9.8 | 1.4% | Jun 28, 2024 | Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to ex... |
| CVE-2024-30110 | CRITICAL | 9.8 | 0.5% | Jun 28, 2024 | HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A maliciou... |
| CVE-2024-39349 | CRITICAL | 9.8 | 1.4% | Jun 28, 2024 | A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjans... |
| CVE-2024-37282 | CRITICAL | 9.8 | 0.6% | Jun 28, 2024 | It was identified that under certain specific preconditions, an API key that was originally created with a specific priv... |
| CVE-2024-6071 | CRITICAL | 10 | 1.1% | Jun 27, 2024 | PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to... |
| CVE-2024-39705 | CRITICAL | 9.8 | 1.3% | Jun 27, 2024 | NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data ... |
| CVE-2024-36059 | CRITICAL | 9.4 | 0.7% | Jun 27, 2024 | Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers t... |
| CVE-2024-36072 | CRITICAL | 9.8 | 1.0% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-2973 | CRITICAL | 10 | 1.1% | Jun 27, 2024 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or co... |
| CVE-2024-6127 | CRITICAL | 9.8 | 10.3% | Jun 27, 2024 | BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote... |
| CVE-2024-39208 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. |
| CVE-2024-5980 | CRITICAL | 9.8 | 1.3% | Jun 27, 2024 | A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path t... |
| CVE-2024-5826 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt i... |
| CVE-2024-5822 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatG... |
| CVE-2024-5751 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulner... |
| CVE-2024-3330 | CRITICAL | 9.9 | 0.6% | Jun 27, 2024 | Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In th... |
| CVE-2024-2882 | CRITICAL | 9.3 | 0.7% | Jun 27, 2024 | SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. T... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now