2024 CVE Vulnerabilities

39,152 CVEs published in 2024.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2024-35777LOW3.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto...
CVE-2024-38372LOW2Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(...
CVE-2024-6580LOW2.3The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re...
CVE-2024-37234LOW3.5URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad...
CVE-2024-40594LOW2.3The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l...
CVE-2024-32754LOW3.1Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i...
CVE-2024-29508LOW3.3Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th...
CVE-2024-6126LOW3.2A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa...
CVE-2024-39353LOW2.7Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them ...
CVE-2024-39324LOW3.8aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2...
CVE-2024-34600LOW3.3Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows loc...
CVE-2024-34599LOW3.3Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Ti...
CVE-2024-34597LOW3.3Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary docume...
CVE-2024-34586LOW3.3Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure ...
CVE-2024-34583LOW3.3Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifi...
CVE-2024-20900LOW3.3Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode with...
CVE-2024-36278LOW3.3in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2024-31071LOW3.3in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
CVE-2024-36995LOW3.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-39846LOW3.5NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz...
CVE-2024-39307LOW3.5Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside...
CVE-2024-39302LOW3.7BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be...
CVE-2024-3995LOW2In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
CVE-2024-38531LOW3.6Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui...
CVE-2024-29038LOW3.3tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate ar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now