2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-0153HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, A...
CVE-2024-3123HIGH7.2CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attac...
CVE-2024-20077HIGH7.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ...
CVE-2024-20076HIGH7.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service ...
CVE-2024-6417HIGH7.5A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by...
CVE-2024-34703HIGH7.5Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-31902HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec...
CVE-2024-39840HIGH8.8Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the...
CVE-2024-2386HIGH8.8The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' paramete...
CVE-2024-5598HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an...
CVE-2024-38532HIGH7.1The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cry...
CVE-2024-38525HIGH7.5dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme...
CVE-2024-37370HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS...
CVE-2024-5712HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the late...
CVE-2024-38528HIGH7.5nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing li...
CVE-2024-38514HIGH7.4NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lac...
CVE-2024-38322HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp...
CVE-2024-35116HIGH7.5IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error app...
CVE-2024-27629HIGH7.8An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name ...
CVE-2024-27628HIGH8.1Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method...
CVE-2024-38374HIGH7.5The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida...
CVE-2024-37905HIGH8.8authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me...
CVE-2024-31919HIGH7.5IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service at...
CVE-2024-31912HIGH8.8IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du...
CVE-2024-29039HIGH8.1tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to man...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now