2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23907 | HIGH | 7.8 | 0.1% | Aug 14, 2024 | Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authen... |
| CVE-2024-23499 | HIGH | 7.5 | 0.5% | Aug 14, 2024 | Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E81... |
| CVE-2024-23497 | HIGH | 8.8 | 0.2% | Aug 14, 2024 | Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before versi... |
| CVE-2024-23495 | HIGH | 7.8 | 0.1% | Aug 14, 2024 | Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authen... |
| CVE-2024-23491 | HIGH | 7.3 | 0.2% | Aug 14, 2024 | Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticat... |
| CVE-2024-23489 | HIGH | 7.3 | 0.2% | Aug 14, 2024 | Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to po... |
| CVE-2024-22184 | HIGH | 7.8 | 0.1% | Aug 14, 2024 | Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an... |
| CVE-2024-21801 | HIGH | 8.3 | 0.2% | Aug 14, 2024 | Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privi... |
| CVE-2024-21787 | HIGH | 7.1 | 0.1% | Aug 14, 2024 | Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentiall... |
| CVE-2024-21784 | HIGH | 7.8 | 0.1% | Aug 14, 2024 | Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated u... |
| CVE-2024-39403 | HIGH | 7.6 | 0.5% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting... |
| CVE-2024-39402 | HIGH | 8.4 | 1.5% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of... |
| CVE-2024-39401 | HIGH | 8.4 | 1.5% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of... |
| CVE-2024-39400 | HIGH | 8.1 | 0.6% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Script... |
| CVE-2024-39399 | HIGH | 7.7 | 0.9% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a P... |
| CVE-2024-39398 | HIGH | 7.4 | 0.8% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Ex... |
| CVE-2024-4389 | HIGH | 8.8 | 1.0% | Aug 14, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2024-41864 | HIGH | 7.8 | 0.3% | Aug 14, 2024 | Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2024-41858 | HIGH | 7.8 | 0.3% | Aug 14, 2024 | InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resu... |
| CVE-2024-7729 | HIGH | 7.5 | 0.6% | Aug 14, 2024 | The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG... |
| CVE-2024-7728 | HIGH | 7.2 | 0.7% | Aug 14, 2024 | The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi... |
| CVE-2024-38653 | HIGH | 7.5 | 92.0% | Aug 14, 2024 | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t... |
| CVE-2024-37399 | HIGH | 7.5 | 27.8% | Aug 14, 2024 | A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to c... |
| CVE-2024-37373 | HIGH | 7.2 | 1.6% | Aug 14, 2024 | Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with... |
| CVE-2024-36136 | HIGH | 7.5 | 2.2% | Aug 14, 2024 | An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now