2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22779 | CRITICAL | 9.8 | 1.9% | Feb 2, 2024 | Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbit... |
| CVE-2024-21764 | CRITICAL | 9.8 | 0.6% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may ... |
| CVE-2024-1039 | CRITICAL | 9.8 | 0.7% | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an ... |
| CVE-2024-24561 | CRITICAL | 9.8 | 0.9% | Feb 1, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds... |
| CVE-2024-23832 | CRITICAL | 9.8 | 1.9% | Feb 1, 2024 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut... |
| CVE-2024-24754 | CRITICAL | 9.8 | 0.6% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ... |
| CVE-2024-23653 | CRITICAL | 9.8 | 3.0% | Jan 31, 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I... |
| CVE-2024-23652 | CRITICAL | 9.1 | 2.0% | Jan 31, 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A... |
| CVE-2024-1117 | CRITICAL | 9.8 | 0.7% | Jan 31, 2024 | A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the... |
| CVE-2024-1116 | CRITICAL | 9.8 | 0.8% | Jan 31, 2024 | A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of t... |
| CVE-2024-1115 | CRITICAL | 9.8 | 1.9% | Jan 31, 2024 | A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function dlfile of th... |
| CVE-2024-1114 | CRITICAL | 9.8 | 0.9% | Jan 31, 2024 | A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function... |
| CVE-2024-1113 | CRITICAL | 9.8 | 0.6% | Jan 31, 2024 | A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnit... |
| CVE-2024-21917 | CRITICAL | 9.1 | 0.9% | Jan 31, 2024 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the s... |
| CVE-2024-24579 | CRITICAL | 9.8 | 0.4% | Jan 31, 2024 | stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1,... |
| CVE-2024-1112 | CRITICAL | 9.8 | 1.6% | Jan 31, 2024 | Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. Thi... |
| CVE-2024-1012 | CRITICAL | 9.8 | 0.9% | Jan 31, 2024 | A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unkn... |
| CVE-2024-23745 | CRITICAL | 9.8 | 2.0% | Jan 31, 2024 | In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to exec... |
| CVE-2024-1036 | CRITICAL | 9.8 | 0.9% | Jan 30, 2024 | A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon o... |
| CVE-2024-21653 | CRITICAL | 9.8 | 0.5% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-1035 | CRITICAL | 9.8 | 0.8% | Jan 30, 2024 | A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function... |
| CVE-2024-24333 | CRITICAL | 9.8 | 1.7% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc paramet... |
| CVE-2024-24332 | CRITICAL | 9.8 | 1.7% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url paramete... |
| CVE-2024-24331 | CRITICAL | 9.8 | 1.6% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param... |
| CVE-2024-24330 | CRITICAL | 9.8 | 1.5% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enab... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now