2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7013 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execut... |
| CVE-2024-6508 | HIGH | 8 | 0.6% | Aug 21, 2024 | An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit gr... |
| CVE-2024-38305 | HIGH | 7.3 | 0.3% | Aug 21, 2024 | Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the install... |
| CVE-2024-43882 | HIGH | 7 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid... |
| CVE-2024-43881 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping re... |
| CVE-2024-43878 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When ther... |
| CVE-2024-43877 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In ... |
| CVE-2024-43873 | HIGH | 7.8 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow The... |
| CVE-2024-22281 | HIGH | 7.5 | 0.7% | Aug 20, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacke... |
| CVE-2024-43403 | HIGH | 8.8 | 0.5% | Aug 20, 2024 | Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, ... |
| CVE-2024-42363 | HIGH | 8.8 | 1.1% | Aug 20, 2024 | Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController.... |
| CVE-2024-42362 | HIGH | 8.8 | 1.3% | Aug 20, 2024 | Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe dese... |
| CVE-2024-41657 | HIGH | 8.8 | 0.7% | Aug 20, 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earli... |
| CVE-2024-41659 | HIGH | 8.1 | 0.6% | Aug 20, 2024 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier wh... |
| CVE-2024-31842 | HIGH | 8.8 | 0.4% | Aug 20, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user ... |
| CVE-2024-42619 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen... |
| CVE-2024-38175 | HIGH | 8.8 | 0.8% | Aug 20, 2024 | An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta... |
| CVE-2024-42612 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen... |
| CVE-2024-35214 | HIGH | 7.1 | 0.2% | Aug 20, 2024 | A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.... |
| CVE-2024-27187 | HIGH | 7.5 | 0.4% | Aug 20, 2024 | Improper Access Controls allows backend users to overwrite their username when disallowed. |
| CVE-2024-43406 | HIGH | 8.8 | 0.9% | Aug 20, 2024 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev... |
| CVE-2024-42662 | HIGH | 7.5 | 0.5% | Aug 20, 2024 | An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request. |
| CVE-2024-42621 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php |
| CVE-2024-42618 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karm... |
| CVE-2024-42617 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now