2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54131 | HIGH | 7.3 | 0.2% | Dec 3, 2024 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ... |
| CVE-2024-51772 | HIGH | 8 | 0.4% | Dec 3, 2024 | An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti... |
| CVE-2024-45757 | HIGH | 7.2 | 0.4% | Dec 3, 2024 | An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set... |
| CVE-2024-51771 | HIGH | 8.8 | 0.7% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-51114 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar... |
| CVE-2024-50948 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s... |
| CVE-2024-48080 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i... |
| CVE-2024-12053 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co... |
| CVE-2024-52547 | HIGH | 7.2 | 0.7% | Dec 3, 2024 | An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit... |
| CVE-2024-41777 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k... |
| CVE-2024-41775 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ... |
| CVE-2024-52805 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf... |
| CVE-2024-37302 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a... |
| CVE-2024-29404 | HIGH | 7.8 | 0.5% | Dec 3, 2024 | An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co... |
| CVE-2024-54000 | HIGH | 7.5 | 0.4% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-11391 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2024-42422 | HIGH | 7.5 | 0.3% | Dec 3, 2024 | Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut... |
| CVE-2024-10074 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through ... |
| CVE-2024-47476 | HIGH | 7.8 | 0.1% | Dec 3, 2024 | Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vuln... |
| CVE-2024-45106 | HIGH | 8.1 | 0.5% | Dec 3, 2024 | Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us... |
| CVE-2024-49420 | HIGH | 7.5 | 0.5% | Dec 3, 2024 | Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attacke... |
| CVE-2024-49413 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t... |
| CVE-2024-49410 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c... |
| CVE-2024-45068 | HIGH | 7.1 | 0.3% | Dec 3, 2024 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. ... |
| CVE-2024-9200 | HIGH | 7.2 | 1.1% | Dec 3, 2024 | A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG400... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now