2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38164 | HIGH | 8.8 | 0.9% | Jul 23, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne... |
| CVE-2024-0981 | HIGH | 7.1 | 0.3% | Jul 23, 2024 | Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T... |
| CVE-2024-41668 | HIGH | 8.3 | 0.6% | Jul 23, 2024 | The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se... |
| CVE-2024-41178 | HIGH | 7.5 | 0.7% | Jul 23, 2024 | Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e... |
| CVE-2024-6714 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th... |
| CVE-2024-4076 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result... |
| CVE-2024-41655 | HIGH | 7.5 | 0.8% | Jul 23, 2024 | TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4... |
| CVE-2024-40060 | HIGH | 7.5 | 0.6% | Jul 23, 2024 | go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function. |
| CVE-2024-1975 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from... |
| CVE-2024-1737 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP... |
| CVE-2024-0760 | HIGH | 7.5 | 4.7% | Jul 23, 2024 | A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta... |
| CVE-2024-5602 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra... |
| CVE-2024-4081 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ... |
| CVE-2024-4080 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar... |
| CVE-2024-4079 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec... |
| CVE-2024-7014 | HIGH | 8.1 | 1.3% | Jul 23, 2024 | EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ... |
| CVE-2024-6420 | HIGH | 8.6 | 1.8% | Jul 23, 2024 | The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect W... |
| CVE-2024-6885 | HIGH | 8.1 | 1.1% | Jul 23, 2024 | The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file... |
| CVE-2024-6828 | HIGH | 7.2 | 1.0% | Jul 23, 2024 | The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization... |
| CVE-2024-6717 | HIGH | 8.6 | 0.4% | Jul 23, 2024 | HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to p... |
| CVE-2024-6913 | HIGH | 8.8 | 1.4% | Jul 22, 2024 | Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windo... |
| CVE-2024-6911 | HIGH | 7.5 | 4.9% | Jul 22, 2024 | Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P... |
| CVE-2024-6791 | HIGH | 7.8 | 0.5% | Jul 22, 2024 | A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote co... |
| CVE-2024-6675 | HIGH | 7.8 | 0.4% | Jul 22, 2024 | A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Succ... |
| CVE-2024-6121 | HIGH | 7.8 | 0.3% | Jul 22, 2024 | An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now