2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3043 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their net... |
| CVE-2024-5548 | HIGH | 7.5 | 1.0% | Jun 27, 2024 | A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-pro... |
| CVE-2024-5547 | HIGH | 7.5 | 1.0% | Jun 27, 2024 | A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository,... |
| CVE-2024-5334 | HIGH | 7.5 | 2.1% | Jun 27, 2024 | A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerabili... |
| CVE-2024-31916 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho... |
| CVE-2024-24792 | HIGH | 7.5 | 0.7% | Jun 27, 2024 | Parsing a corrupt or malicious image with invalid color indices can cause a panic. |
| CVE-2024-39373 | HIGH | 7.2 | 1.2% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings ... |
| CVE-2024-39158 | HIGH | 8.8 | 0.3% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mud... |
| CVE-2024-39154 | HIGH | 8.8 | 0.3% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud... |
| CVE-2024-22232 | HIGH | 7.7 | 0.8% | Jun 27, 2024 | A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user ca... |
| CVE-2024-6054 | HIGH | 8.8 | 0.8% | Jun 27, 2024 | The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2024-6323 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior t... |
| CVE-2024-5655 | HIGH | 8.8 | 7.5% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-28982 | HIGH | 8.2 | 0.4% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly... |
| CVE-2024-36829 | HIGH | 7.5 | 0.4% | Jun 26, 2024 | Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted que... |
| CVE-2024-23767 | HIGH | 8.8 | 0.4% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated ch... |
| CVE-2024-23766 | HIGH | 7.5 | 0.4% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An u... |
| CVE-2024-33329 | HIGH | 7.5 | 0.7% | Jun 26, 2024 | A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access interna... |
| CVE-2024-6354 | HIGH | 7.2 | 0.8% | Jun 26, 2024 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows a... |
| CVE-2024-4758 | HIGH | 7.6 | 0.3% | Jun 26, 2024 | The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, whi... |
| CVE-2024-34581 | HIGH | 7.3 | 0.2% | Jun 26, 2024 | The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a ... |
| CVE-2024-37140 | HIGH | 8.8 | 1.2% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection v... |
| CVE-2024-29176 | HIGH | 8.8 | 0.6% | Jun 26, 2024 | Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A ... |
| CVE-2024-5460 | HIGH | 8.1 | 0.5% | Jun 26, 2024 | A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric... |
| CVE-2024-38526 | HIGH | 7.2 | 3.8% | Jun 26, 2024 | pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript fil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now