2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7557 | HIGH | 8.8 | 0.9% | Aug 12, 2024 | A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models w... |
| CVE-2024-7272 | HIGH | 8.8 | 1.1% | Aug 12, 2024 | A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio... |
| CVE-2024-7006 | HIGH | 7.5 | 1.5% | Aug 12, 2024 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me... |
| CVE-2024-6760 | HIGH | 7.5 | 0.7% | Aug 12, 2024 | A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it sh... |
| CVE-2024-5800 | HIGH | 7.5 | 0.3% | Aug 12, 2024 | Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before... |
| CVE-2024-5651 | HIGH | 8.8 | 1.4% | Aug 12, 2024 | A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) pr... |
| CVE-2024-5527 | HIGH | 8.8 | 4.7% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing co... |
| CVE-2024-5487 | HIGH | 8.8 | 4.7% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a... |
| CVE-2024-42468 | HIGH | 7.5 | 0.8% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C... |
| CVE-2024-42370 | HIGH | 8.3 | 0.6% | Aug 12, 2024 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-pr... |
| CVE-2024-42167 | HIGH | 7.2 | 0.5% | Aug 12, 2024 | The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec... |
| CVE-2024-42166 | HIGH | 7.2 | 0.5% | Aug 12, 2024 | The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special... |
| CVE-2024-42163 | HIGH | 8.1 | 0.3% | Aug 12, 2024 | Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over t... |
| CVE-2024-41936 | HIGH | 7.5 | 1.7% | Aug 12, 2024 | A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software v... |
| CVE-2024-40488 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lea... |
| CVE-2024-40487 | HIGH | 7.6 | 1.1% | Aug 12, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0... |
| CVE-2024-40479 | HIGH | 8.1 | 0.8% | Aug 12, 2024 | A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers ... |
| CVE-2024-40476 | HIGH | 8 | 0.3% | Aug 12, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. ... |
| CVE-2024-40475 | HIGH | 8.8 | 0.5% | Aug 12, 2024 | SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re... |
| CVE-2024-39815 | HIGH | 7.5 | 0.8% | Aug 12, 2024 | Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays ... |
| CVE-2024-39338 | HIGH | 7.5 | 1.4% | Aug 12, 2024 | axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative... |
| CVE-2024-38218 | HIGH | 7.8 | 0.6% | Aug 12, 2024 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability |
| CVE-2024-37826 | HIGH | 7.5 | 1.2% | Aug 12, 2024 | A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP... |
| CVE-2024-36462 | HIGH | 7.5 | 0.9% | Aug 12, 2024 | Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources... |
| CVE-2024-36461 | HIGH | 8.8 | 0.8% | Aug 12, 2024 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now