2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0153 | HIGH | 7.8 | 0.2% | Jul 1, 2024 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, A... |
| CVE-2024-3123 | HIGH | 7.2 | 0.6% | Jul 1, 2024 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attac... |
| CVE-2024-20077 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ... |
| CVE-2024-20076 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ... |
| CVE-2024-6417 | HIGH | 7.5 | 0.5% | Jun 30, 2024 | A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by... |
| CVE-2024-34703 | HIGH | 7.5 | 0.5% | Jun 30, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-31902 | HIGH | 8.8 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec... |
| CVE-2024-39840 | HIGH | 8.8 | 0.6% | Jun 29, 2024 | Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the... |
| CVE-2024-2386 | HIGH | 8.8 | 0.5% | Jun 29, 2024 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' paramete... |
| CVE-2024-5598 | HIGH | 7.5 | 0.6% | Jun 29, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an... |
| CVE-2024-38532 | HIGH | 7.1 | 0.2% | Jun 28, 2024 | The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cry... |
| CVE-2024-38525 | HIGH | 7.5 | 0.4% | Jun 28, 2024 | dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme... |
| CVE-2024-37370 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS... |
| CVE-2024-5712 | HIGH | 8.1 | 0.3% | Jun 28, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the late... |
| CVE-2024-38528 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing li... |
| CVE-2024-38514 | HIGH | 7.4 | 2.2% | Jun 28, 2024 | NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lac... |
| CVE-2024-38322 | HIGH | 7.5 | 0.4% | Jun 28, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp... |
| CVE-2024-35116 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error app... |
| CVE-2024-27629 | HIGH | 7.8 | 0.2% | Jun 28, 2024 | An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name ... |
| CVE-2024-27628 | HIGH | 8.1 | 0.7% | Jun 28, 2024 | Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method... |
| CVE-2024-38374 | HIGH | 7.5 | 0.6% | Jun 28, 2024 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida... |
| CVE-2024-37905 | HIGH | 8.8 | 0.8% | Jun 28, 2024 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me... |
| CVE-2024-31919 | HIGH | 7.5 | 0.5% | Jun 28, 2024 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service at... |
| CVE-2024-31912 | HIGH | 8.8 | 0.4% | Jun 28, 2024 | IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du... |
| CVE-2024-29039 | HIGH | 8.1 | 1.0% | Jun 28, 2024 | tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to man... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now