2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21832 | LOW | 3.5 | 0.2% | Jul 9, 2024 | A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re... |
| CVE-2024-6501 | LOW | 3.1 | 0.4% | Jul 9, 2024 | A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 c... |
| CVE-2024-28067 | LOW | 3.7 | 0.3% | Jul 9, 2024 | A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode o... |
| CVE-2024-37253 | LOW | 2.7 | 0.3% | Jul 9, 2024 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi... |
| CVE-2024-35777 | LOW | 3.5 | 0.4% | Jul 9, 2024 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto... |
| CVE-2024-38372 | LOW | 2 | 0.5% | Jul 8, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(... |
| CVE-2024-37234 | LOW | 3.5 | 0.3% | Jul 6, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad... |
| CVE-2024-40594 | LOW | 2.3 | 0.1% | Jul 6, 2024 | The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l... |
| CVE-2024-32754 | LOW | 3.1 | 0.2% | Jul 4, 2024 | Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i... |
| CVE-2024-29508 | LOW | 3.3 | 0.4% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th... |
| CVE-2024-6126 | LOW | 3.2 | 0.3% | Jul 3, 2024 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa... |
| CVE-2024-6470 | LOW | 2.7 | 0.4% | Jul 3, 2024 | A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun... |
| CVE-2024-39353 | LOW | 2.7 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them ... |
| CVE-2024-39324 | LOW | 3.8 | 0.4% | Jul 2, 2024 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2... |
| CVE-2024-34600 | LOW | 3.3 | 0.1% | Jul 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows loc... |
| CVE-2024-34599 | LOW | 3.3 | 0.1% | Jul 2, 2024 | Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Ti... |
| CVE-2024-34597 | LOW | 3.3 | 0.2% | Jul 2, 2024 | Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary docume... |
| CVE-2024-34586 | LOW | 3.3 | 0.1% | Jul 2, 2024 | Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure ... |
| CVE-2024-34583 | LOW | 3.3 | 0.1% | Jul 2, 2024 | Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifi... |
| CVE-2024-20900 | LOW | 3.3 | 0.1% | Jul 2, 2024 | Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode with... |
| CVE-2024-36278 | LOW | 3.3 | 0.1% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2024-31071 | LOW | 3.3 | 0.1% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion. |
| CVE-2024-36995 | LOW | 3.5 | 0.2% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-39846 | LOW | 3.5 | 0.2% | Jun 29, 2024 | NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz... |
| CVE-2024-39307 | LOW | 3.5 | 0.5% | Jun 28, 2024 | Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now