2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42477HIGH7.5llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buff...
CVE-2024-33535HIGH7.5An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local fil...
CVE-2024-27442HIGH7.8An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is int...
CVE-2024-7697HIGH7.5Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
CVE-2024-7694HIGH7.2ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with ...
CVE-2024-7693HIGH7.5Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing ...
CVE-2024-7661HIGH8.8A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problema...
CVE-2024-7659HIGH7.5A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function gen...
CVE-2024-7589HIGH8.1A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked wh...
CVE-2024-7557HIGH8.8A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models w...
CVE-2024-7272HIGH8.8A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio...
CVE-2024-7006HIGH7.5A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me...
CVE-2024-6760HIGH7.5A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it sh...
CVE-2024-5800HIGH7.5Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before...
CVE-2024-5651HIGH8.8A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) pr...
CVE-2024-5527HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing co...
CVE-2024-5487HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a...
CVE-2024-42468HIGH7.5openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C...
CVE-2024-42370HIGH8.3Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-pr...
CVE-2024-42167HIGH7.2The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec...
CVE-2024-42166HIGH7.2The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special...
CVE-2024-42163HIGH8.1Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over t...
CVE-2024-41936HIGH7.5A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software v...
CVE-2024-40488HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lea...
CVE-2024-40487HIGH7.6A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now