2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38453 | HIGH | 7.5 | 0.4% | Jul 3, 2024 | The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current vers... |
| CVE-2024-2376 | HIGH | 8.8 | 0.4% | Jul 3, 2024 | The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-6453 | HIGH | 8.8 | 0.6% | Jul 2, 2024 | A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this... |
| CVE-2024-24791 | HIGH | 7.5 | 1.4% | Jul 2, 2024 | The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" hea... |
| CVE-2024-6452 | HIGH | 8.8 | 0.5% | Jul 2, 2024 | A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is a... |
| CVE-2024-6382 | HIGH | 7.5 | 0.3% | Jul 2, 2024 | Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. T... |
| CVE-2024-39894 | HIGH | 7.5 | 1.6% | Jul 2, 2024 | OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sud... |
| CVE-2024-39206 | HIGH | 7.5 | 0.5% | Jul 2, 2024 | An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials ... |
| CVE-2024-4467 | HIGH | 7.8 | 0.3% | Jul 2, 2024 | A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `... |
| CVE-2024-3826 | HIGH | 8.6 | 0.3% | Jul 2, 2024 | In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On... |
| CVE-2024-39323 | HIGH | 7.1 | 0.4% | Jul 2, 2024 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions ... |
| CVE-2024-26314 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and ... |
| CVE-2024-25088 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute... |
| CVE-2024-25086 | HIGH | 7.8 | 0.3% | Jul 2, 2024 | Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute... |
| CVE-2024-22106 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute ar... |
| CVE-2024-4897 | HIGH | 8.4 | 0.4% | Jul 2, 2024 | parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on ll... |
| CVE-2024-38519 | HIGH | 7.8 | 0.3% | Jul 2, 2024 | `yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-d... |
| CVE-2024-34122 | HIGH | 7.8 | 0.3% | Jul 2, 2024 | Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a c... |
| CVE-2024-34596 | HIGH | 7.5 | 0.5% | Jul 2, 2024 | Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for... |
| CVE-2024-34595 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch... |
| CVE-2024-34593 | HIGH | 8.8 | 0.6% | Jul 2, 2024 | Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows re... |
| CVE-2024-34585 | HIGH | 7.8 | 0.1% | Jul 2, 2024 | Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privil... |
| CVE-2024-20901 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attac... |
| CVE-2024-20893 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigg... |
| CVE-2024-20892 | HIGH | 7.8 | 0.1% | Jul 2, 2024 | Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now