2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32211 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive informa... |
| CVE-2024-32210 | MEDIUM | 5.3 | 0.4% | May 1, 2024 | The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default ... |
| CVE-2024-30176 | MEDIUM | 5.3 | 0.4% | May 1, 2024 | In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared w... |
| CVE-2024-29010 | HIGH | 7.1 | 0.6% | May 1, 2024 | The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially... |
| CVE-2024-33518 | MEDIUM | 5.3 | 0.5% | May 1, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ... |
| CVE-2024-33517 | HIGH | 7.5 | 0.6% | May 1, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ... |
| CVE-2024-33516 | HIGH | 7.5 | 0.6% | May 1, 2024 | An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provi... |
| CVE-2024-33515 | HIGH | 7.5 | 0.6% | May 1, 2024 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco... |
| CVE-2024-33514 | HIGH | 7.5 | 0.6% | May 1, 2024 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco... |
| CVE-2024-33513 | MEDIUM | 5.9 | 0.5% | May 1, 2024 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco... |
| CVE-2024-28764 | HIGH | 7.8 | 0.2% | May 1, 2024 | IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection.... |
| CVE-2024-25015 | HIGH | 7.5 | 0.9% | May 1, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending... |
| CVE-2024-23480 | CRITICAL | 9.8 | 0.3% | May 1, 2024 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Clien... |
| CVE-2024-23457 | HIGH | 7.8 | 0.2% | May 1, 2024 | The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninst... |
| CVE-2024-20378 | HIGH | 7.5 | 0.8% | May 1, 2024 | A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote ... |
| CVE-2024-20376 | HIGH | 7.5 | 0.9% | May 1, 2024 | A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote ... |
| CVE-2024-20357 | MEDIUM | 5.9 | 0.5% | May 1, 2024 | A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiat... |
| CVE-2024-33820 | HIGH | 7.5 | 0.6% | May 1, 2024 | Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overf... |
| CVE-2024-28893 | HIGH | 7.7 | 0.3% | May 1, 2024 | Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configur... |
| CVE-2024-33512 | CRITICAL | 9.8 | 14.6% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to... |
| CVE-2024-33511 | CRITICAL | 9.8 | 14.6% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticate... |
| CVE-2024-26305 | CRITICAL | 9.8 | 15.2% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code... |
| CVE-2024-26304 | CRITICAL | 9.8 | 44.0% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r... |
| CVE-2024-24912 | MEDIUM | 6.7 | 0.2% | May 1, 2024 | A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions ... |
| CVE-2024-4368 | HIGH | 8.8 | 1.1% | May 1, 2024 | Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now