2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38456 | HIGH | 7.8 | 0.2% | Sep 3, 2024 | HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and fo... |
| CVE-2024-6119 | HIGH | 7.5 | 66.6% | Sep 3, 2024 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte... |
| CVE-2024-42991 | HIGH | 8.1 | 0.8% | Sep 3, 2024 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. |
| CVE-2024-8383 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that... |
| CVE-2024-8382 | HIGH | 8.8 | 0.6% | Sep 3, 2024 | Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th... |
| CVE-2024-6232 | HIGH | 7.5 | 2.2% | Sep 3, 2024 | There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking... |
| CVE-2024-6473 | HIGH | 7.8 | 0.7% | Sep 3, 2024 | Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. |
| CVE-2024-45588 | HIGH | 8.1 | 0.4% | Sep 3, 2024 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A... |
| CVE-2024-8374 | HIGH | 7.8 | 0.4% | Sep 3, 2024 | UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/p... |
| CVE-2024-45587 | HIGH | 8.8 | 0.4% | Sep 3, 2024 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A... |
| CVE-2024-45586 | HIGH | 8.8 | 0.4% | Sep 3, 2024 | This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi... |
| CVE-2024-3655 | HIGH | 7.8 | 0.2% | Sep 3, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2024-38811 | HIGH | 7.8 | 0.3% | Sep 3, 2024 | VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var... |
| CVE-2024-7203 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and... |
| CVE-2024-5412 | HIGH | 7.5 | 0.7% | Sep 3, 2024 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 cou... |
| CVE-2024-42060 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US... |
| CVE-2024-42059 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US... |
| CVE-2024-42058 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series... |
| CVE-2024-42057 | HIGH | 8.1 | 1.3% | Sep 3, 2024 | A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.3... |
| CVE-2024-1621 | HIGH | 7.5 | 0.4% | Sep 2, 2024 | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compr... |
| CVE-2024-6921 | HIGH | 7.5 | 0.2% | Sep 2, 2024 | Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev... |
| CVE-2024-45388 | HIGH | 7.5 | 55.9% | Sep 2, 2024 | Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap... |
| CVE-2024-45311 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is... |
| CVE-2024-42471 | HIGH | 7.5 | 3.0% | Sep 2, 2024 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch ... |
| CVE-2024-5148 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now