2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36460 | HIGH | 8.1 | 0.6% | Aug 12, 2024 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te... |
| CVE-2024-36035 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec... |
| CVE-2024-36034 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report... |
| CVE-2024-30188 | HIGH | 8.1 | 6.0% | Aug 12, 2024 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional reso... |
| CVE-2024-29831 | HIGH | 8.8 | 1.2% | Aug 12, 2024 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox... |
| CVE-2024-29082 | HIGH | 8.6 | 0.8% | Aug 12, 2024 | Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa... |
| CVE-2024-22116 | HIGH | 7.2 | 1.6% | Aug 12, 2024 | An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ... |
| CVE-2024-21881 | HIGH | 8.6 | 0.3% | Aug 12, 2024 | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp... |
| CVE-2024-21880 | HIGH | 7.2 | 2.3% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ... |
| CVE-2024-21879 | HIGH | 8.8 | 2.5% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet... |
| CVE-2024-0113 | HIGH | 8.8 | 1.0% | Aug 12, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau... |
| CVE-2024-39287 | HIGH | 7.5 | 0.3% | Aug 8, 2024 | Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa... |
| CVE-2024-37382 | HIGH | 7.2 | 0.4% | Aug 8, 2024 | An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows att... |
| CVE-2024-0104 | HIGH | 8.8 | 0.3% | Aug 8, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us... |
| CVE-2024-42365 | HIGH | 8.8 | 4.7% | Aug 8, 2024 | Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9... |
| CVE-2024-0108 | HIGH | 8.8 | 0.2% | Aug 8, 2024 | NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean u... |
| CVE-2024-0107 | HIGH | 7.8 | 0.5% | Aug 8, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-0101 | HIGH | 7.5 | 0.5% | Aug 8, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter ... |
| CVE-2024-42356 | HIGH | 7.2 | 0.6% | Aug 8, 2024 | Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into a... |
| CVE-2024-41942 | HIGH | 7.2 | 0.6% | Aug 8, 2024 | JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and ... |
| CVE-2024-7348 | HIGH | 7.5 | 1.6% | Aug 8, 2024 | Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary... |
| CVE-2024-3659 | HIGH | 7.2 | 1.6% | Aug 8, 2024 | Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen... |
| CVE-2024-3035 | HIGH | 8.1 | 0.4% | Aug 8, 2024 | A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior t... |
| CVE-2024-2800 | HIGH | 7.5 | 0.7% | Aug 8, 2024 | ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 pri... |
| CVE-2024-6329 | HIGH | 7.5 | 0.4% | Aug 8, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now