2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20891 | HIGH | 7.8 | 0.1% | Jul 2, 2024 | Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to ... |
| CVE-2024-20890 | HIGH | 8.8 | 0.2% | Jul 2, 2024 | Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior. |
| CVE-2024-20888 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activit... |
| CVE-2024-4836 | HIGH | 7.5 | 2.6% | Jul 2, 2024 | Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as t... |
| CVE-2024-37479 | HIGH | 8.8 | 0.4% | Jul 2, 2024 | Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widge... |
| CVE-2024-32853 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A... |
| CVE-2024-32852 | HIGH | 7.5 | 0.2% | Jul 2, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerab... |
| CVE-2024-5767 | HIGH | 8.8 | 0.3% | Jul 2, 2024 | The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well ... |
| CVE-2024-5606 | HIGH | 8.8 | 0.6% | Jul 2, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_... |
| CVE-2024-5349 | HIGH | 8.8 | 1.0% | Jul 2, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2024-4679 | HIGH | 7.8 | 0.2% | Jul 2, 2024 | Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNM... |
| CVE-2024-37765 | HIGH | 8.8 | 0.8% | Jul 1, 2024 | Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page. |
| CVE-2024-23736 | HIGH | 8.8 | 0.1% | Jul 1, 2024 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to ma... |
| CVE-2024-32230 | HIGH | 7.8 | 0.4% | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in... |
| CVE-2024-32229 | HIGH | 8.4 | 0.3% | Jul 1, 2024 | FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column. |
| CVE-2024-39249 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in aut... |
| CVE-2024-39573 | HIGH | 7.5 | 35.4% | Jul 1, 2024 | Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules t... |
| CVE-2024-38477 | HIGH | 7.5 | 3.2% | Jul 1, 2024 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server vi... |
| CVE-2024-38473 | HIGH | 8.1 | 25.9% | Jul 1, 2024 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be... |
| CVE-2024-38472 | HIGH | 7.5 | 68.0% | Jul 1, 2024 | SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and maliciou... |
| CVE-2024-37298 | HIGH | 7.5 | 1.1% | Jul 1, 2024 | gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a s... |
| CVE-2024-36997 | HIGH | 8.1 | 0.5% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin... |
| CVE-2024-36991 | HIGH | 7.5 | 13.1% | Jul 1, 2024 | In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on t... |
| CVE-2024-36985 | HIGH | 8.8 | 6.5% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or powe... |
| CVE-2024-36984 | HIGH | 8.8 | 1.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now