2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33582 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code wi... |
| CVE-2024-33581 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker t... |
| CVE-2024-33580 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with ... |
| CVE-2024-33579 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevate... |
| CVE-2024-33578 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated ... |
| CVE-2024-45403 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3... |
| CVE-2024-45397 | HIGH | 7.5 | 0.4% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top... |
| CVE-2024-45396 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attac... |
| CVE-2024-9002 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit... |
| CVE-2024-8531 | HIGH | 7.2 | 0.4% | Oct 11, 2024 | CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Exp... |
| CVE-2024-9855 | HIGH | 7.2 | 0.6% | Oct 11, 2024 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this ... |
| CVE-2024-9164 | HIGH | 8.8 | 0.9% | Oct 11, 2024 | An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prio... |
| CVE-2024-8970 | HIGH | 8.8 | 0.6% | Oct 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 pr... |
| CVE-2024-45317 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allow... |
| CVE-2024-45316 | HIGH | 7.8 | 0.3% | Oct 11, 2024 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12... |
| CVE-2024-9817 | HIGH | 8.8 | 0.5% | Oct 10, 2024 | A vulnerability was found in code-projects Blood Bank System 1.0. It has been classified as critical. This affects an un... |
| CVE-2024-47870 | HIGH | 8.1 | 0.4% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition**... |
| CVE-2024-47868 | HIGH | 7.5 | 0.8% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affe... |
| CVE-2024-47867 | HIGH | 7.5 | 0.2% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity chec... |
| CVE-2024-9816 | HIGH | 7.2 | 0.6% | Oct 10, 2024 | A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue i... |
| CVE-2024-9815 | HIGH | 7.2 | 0.6% | Oct 10, 2024 | A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vu... |
| CVE-2024-47084 | HIGH | 8.3 | 0.5% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin v... |
| CVE-2024-9180 | HIGH | 7.2 | 0.5% | Oct 10, 2024 | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or... |
| CVE-2024-47966 | HIGH | 7.8 | 0.2% | Oct 10, 2024 | Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate use... |
| CVE-2024-47965 | HIGH | 7.8 | 0.2% | Oct 10, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now