2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6890HIGH8.8Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ...
CVE-2024-6707HIGH8.8Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver...
CVE-2024-7143HIGH8.3A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permission...
CVE-2024-7061HIGH7.8Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta ...
CVE-2024-20451HIGH7.5Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco...
CVE-2024-41309HIGH7.8An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted termina...
CVE-2024-41308HIGH7.8An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal enviro...
CVE-2024-42005HIGH7.3An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on...
CVE-2024-41991HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a...
CVE-2024-41990HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filter...
CVE-2024-41989HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to ...
CVE-2024-7579HIGH8.8A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by ...
CVE-2024-43199HIGH7.8Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned ...
CVE-2024-43044HIGH8.8Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins contr...
CVE-2024-7265HIGH8.8Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al...
CVE-2024-7553HIGH7.8Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl...
CVE-2024-5290HIGH7.8An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a lo...
CVE-2024-42062HIGH7.2CloudStack account-users by default use username and password based authentication for API and UI access. Account-users ...
CVE-2024-36132HIGH7.5Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authen...
CVE-2024-36131HIGH8.8An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote atta...
CVE-2024-34623HIGH7.8Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers...
CVE-2024-34622HIGH7.8Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potenti...
CVE-2024-34620HIGH7.8Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privilege...
CVE-2024-34619HIGH8.8Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code...
CVE-2024-34615HIGH7.8Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now