2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38164HIGH8.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-0981HIGH7.1Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T...
CVE-2024-41668HIGH8.3The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se...
CVE-2024-41178HIGH7.5Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e...
CVE-2024-6714HIGH7.8An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th...
CVE-2024-4076HIGH7.5Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result...
CVE-2024-41655HIGH7.5TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4...
CVE-2024-40060HIGH7.5go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
CVE-2024-1975HIGH7.5If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from...
CVE-2024-1737HIGH7.5Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP...
CVE-2024-0760HIGH7.5A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta...
CVE-2024-5602HIGH7.8A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra...
CVE-2024-4081HIGH7.8A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ...
CVE-2024-4080HIGH7.8A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar...
CVE-2024-4079HIGH7.8An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec...
CVE-2024-7014HIGH8.1EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ...
CVE-2024-6420HIGH8.6The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect W...
CVE-2024-6885HIGH8.1The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file...
CVE-2024-6828HIGH7.2The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization...
CVE-2024-6717HIGH8.6HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to p...
CVE-2024-6913HIGH8.8Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windo...
CVE-2024-6911HIGH7.5Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P...
CVE-2024-6791HIGH7.8A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote co...
CVE-2024-6675HIGH7.8A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Succ...
CVE-2024-6121HIGH7.8An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now