2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31977 | HIGH | 8.8 | 1.7% | Jul 24, 2024 | Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s... |
| CVE-2024-22443 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2024-7067 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ... |
| CVE-2024-6197 | HIGH | 7.5 | 4.3% | Jul 24, 2024 | libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi... |
| CVE-2024-39676 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin... |
| CVE-2024-7027 | HIGH | 7.3 | 0.4% | Jul 24, 2024 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ... |
| CVE-2024-6756 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2024-6750 | HIGH | 7.5 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ... |
| CVE-2024-38176 | HIGH | 8.1 | 0.9% | Jul 23, 2024 | An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri... |
| CVE-2024-38164 | HIGH | 8.8 | 0.9% | Jul 23, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne... |
| CVE-2024-0981 | HIGH | 7.1 | 0.3% | Jul 23, 2024 | Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T... |
| CVE-2024-41668 | HIGH | 8.3 | 0.6% | Jul 23, 2024 | The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se... |
| CVE-2024-41178 | HIGH | 7.5 | 0.7% | Jul 23, 2024 | Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e... |
| CVE-2024-6714 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th... |
| CVE-2024-4076 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result... |
| CVE-2024-41655 | HIGH | 7.5 | 0.8% | Jul 23, 2024 | TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4... |
| CVE-2024-40060 | HIGH | 7.5 | 0.6% | Jul 23, 2024 | go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function. |
| CVE-2024-1975 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from... |
| CVE-2024-1737 | HIGH | 7.5 | 2.1% | Jul 23, 2024 | Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP... |
| CVE-2024-0760 | HIGH | 7.5 | 4.7% | Jul 23, 2024 | A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta... |
| CVE-2024-5602 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra... |
| CVE-2024-4081 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ... |
| CVE-2024-4080 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar... |
| CVE-2024-4079 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec... |
| CVE-2024-7014 | HIGH | 8.1 | 1.3% | Jul 23, 2024 | EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now