2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6411 | HIGH | 8.8 | 0.8% | Jul 10, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in al... |
| CVE-2024-39614 | HIGH | 7.5 | 30.1% | Jul 10, 2024 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject t... |
| CVE-2024-38875 | HIGH | 7.5 | 1.2% | Jul 10, 2024 | An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a poten... |
| CVE-2024-21526 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to t... |
| CVE-2024-21525 | HIGH | 8.3 | 0.5% | Jul 10, 2024 | All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the... |
| CVE-2024-21523 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to ... |
| CVE-2024-21522 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to th... |
| CVE-2024-21521 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object w... |
| CVE-2024-38301 | HIGH | 7.8 | 0.1% | Jul 10, 2024 | Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privi... |
| CVE-2024-5792 | HIGH | 8.8 | 0.5% | Jul 10, 2024 | The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all... |
| CVE-2024-6433 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files... |
| CVE-2024-32670 | HIGH | 7 | 0.2% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ... |
| CVE-2024-21417 | HIGH | 8.8 | 0.4% | Jul 10, 2024 | Windows Text Services Framework Elevation of Privilege Vulnerability |
| CVE-2024-39883 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39882 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a... |
| CVE-2024-39881 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond... |
| CVE-2024-39880 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39069 | HIGH | 7.8 | 0.6% | Jul 9, 2024 | An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij... |
| CVE-2024-36676 | HIGH | 7.5 | 0.6% | Jul 9, 2024 | Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ... |
| CVE-2024-35154 | HIGH | 7.2 | 1.2% | Jul 9, 2024 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t... |
| CVE-2024-37829 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafte... |
| CVE-2024-34726 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This co... |
| CVE-2024-34725 | HIGH | 7 | 0.1% | Jul 9, 2024 | In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi... |
| CVE-2024-34724 | HIGH | 7 | 0.1% | Jul 9, 2024 | In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead... |
| CVE-2024-34723 | HIGH | 7.8 | 0.1% | Jul 9, 2024 | In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from back... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now