2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33913 | CRITICAL | 9.6 | 0.3% | May 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects ... |
| CVE-2024-3955 | CRITICAL | 9.8 | 1.1% | May 2, 2024 | URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subs... |
| CVE-2024-32971 | CRITICAL | 9 | 0.7% | May 2, 2024 | Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation ... |
| CVE-2024-32962 | CRITICAL | 10 | 0.8% | May 2, 2024 | xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuratio... |
| CVE-2024-4142 | CRITICAL | 9 | 0.7% | May 1, 2024 | An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog A... |
| CVE-2024-33078 | CRITICAL | 9.8 | 1.1% | May 1, 2024 | Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to r... |
| CVE-2024-23480 | CRITICAL | 9.8 | 0.3% | May 1, 2024 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Clien... |
| CVE-2024-33512 | CRITICAL | 9.8 | 14.6% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to... |
| CVE-2024-33511 | CRITICAL | 9.8 | 14.6% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticate... |
| CVE-2024-26305 | CRITICAL | 9.8 | 15.2% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code... |
| CVE-2024-26304 | CRITICAL | 9.8 | 44.0% | May 1, 2024 | There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r... |
| CVE-2024-33775 | CRITICAL | 9.8 | 1.6% | May 1, 2024 | An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a cr... |
| CVE-2024-33835 | CRITICAL | 9.8 | 0.8% | May 1, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function. |
| CVE-2024-32018 | CRITICAL | 9 | 1.5% | May 1, 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a... |
| CVE-2024-32017 | CRITICAL | 9 | 1.5% | May 1, 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a... |
| CVE-2024-31225 | CRITICAL | 9 | 1.2% | May 1, 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a... |
| CVE-2024-33768 | CRITICAL | 9.8 | 0.8% | May 1, 2024 | lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over. |
| CVE-2024-3411 | CRITICAL | 9.1 | 0.7% | Apr 30, 2024 | Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, all... |
| CVE-2024-33308 | CRITICAL | 9.1 | 0.7% | Apr 30, 2024 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate pr... |
| CVE-2024-33275 | CRITICAL | 9.8 | 0.7% | Apr 30, 2024 | SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privilege... |
| CVE-2024-33273 | CRITICAL | 9.8 | 0.6% | Apr 30, 2024 | SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID f... |
| CVE-2024-33267 | CRITICAL | 9.8 | 0.5% | Apr 30, 2024 | SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the H... |
| CVE-2024-34048 | CRITICAL | 9.8 | 0.6% | Apr 30, 2024 | O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler. |
| CVE-2024-33350 | CRITICAL | 9.8 | 1.8% | Apr 29, 2024 | Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensit... |
| CVE-2024-33435 | CRITICAL | 9.8 | 0.9% | Apr 29, 2024 | Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intellig... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now