2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36311MEDIUM4.6A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker t...
CVE-2024-36310MEDIUM4.6Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds...
CVE-2024-21953MEDIUM5.9Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o...
CVE-2024-54192MEDIUM5.5An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_g...
CVE-2024-52334MEDIUM6.3A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not ...
CVE-2024-51451MEDIUM6.5IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO...
CVE-2024-43181MEDIUM6.3IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe...
CVE-2024-40685MEDIUM4.3IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are...
CVE-2024-39724MEDIUM5.3IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not proper...
CVE-2024-5986CRITICAL9.1A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve...
CVE-2024-5386HIGH8.8In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ...
CVE-2024-4147MEDIUM6.5In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete p...
CVE-2024-2356CRITICAL9.6A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap...
CVE-2024-54263HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-9432MEDIUM6.9Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.  ...
CVE-2024-4027HIGH7.5A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an...
CVE-2024-11976HIGH7.3The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ...
CVE-2024-53252——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-53251——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-53250——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-53249——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-53248——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-45743——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-45742——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
CVE-2024-45730——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now