2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6890 | HIGH | 8.8 | 0.7% | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ... |
| CVE-2024-6707 | HIGH | 8.8 | 1.0% | Aug 7, 2024 | Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver... |
| CVE-2024-7143 | HIGH | 8.3 | 0.6% | Aug 7, 2024 | A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permission... |
| CVE-2024-7061 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta ... |
| CVE-2024-20451 | HIGH | 7.5 | 0.8% | Aug 7, 2024 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco... |
| CVE-2024-41309 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted termina... |
| CVE-2024-41308 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal enviro... |
| CVE-2024-42005 | HIGH | 7.3 | 1.2% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on... |
| CVE-2024-41991 | HIGH | 7.5 | 1.0% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a... |
| CVE-2024-41990 | HIGH | 7.5 | 1.3% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filter... |
| CVE-2024-41989 | HIGH | 7.5 | 1.2% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to ... |
| CVE-2024-7579 | HIGH | 8.8 | 8.4% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by ... |
| CVE-2024-43199 | HIGH | 7.8 | 1.1% | Aug 7, 2024 | Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned ... |
| CVE-2024-43044 | HIGH | 8.8 | 28.8% | Aug 7, 2024 | Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins contr... |
| CVE-2024-7265 | HIGH | 8.8 | 0.5% | Aug 7, 2024 | Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al... |
| CVE-2024-7553 | HIGH | 7.8 | 0.3% | Aug 7, 2024 | Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl... |
| CVE-2024-5290 | HIGH | 7.8 | 0.7% | Aug 7, 2024 | An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a lo... |
| CVE-2024-42062 | HIGH | 7.2 | 0.9% | Aug 7, 2024 | CloudStack account-users by default use username and password based authentication for API and UI access. Account-users ... |
| CVE-2024-36132 | HIGH | 7.5 | 1.2% | Aug 7, 2024 | Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authen... |
| CVE-2024-36131 | HIGH | 8.8 | 2.3% | Aug 7, 2024 | An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote atta... |
| CVE-2024-34623 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers... |
| CVE-2024-34622 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potenti... |
| CVE-2024-34620 | HIGH | 7.8 | 0.1% | Aug 7, 2024 | Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privilege... |
| CVE-2024-34619 | HIGH | 8.8 | 0.5% | Aug 7, 2024 | Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code... |
| CVE-2024-34615 | HIGH | 7.8 | 0.1% | Aug 7, 2024 | Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now