2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37062HIGH7.8Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e...
CVE-2024-37061HIGH8.8Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a malicious...
CVE-2024-37060HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling...
CVE-2024-37059HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling ...
CVE-2024-37058HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling ...
CVE-2024-37057HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabli...
CVE-2024-37056HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling...
CVE-2024-37055HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling...
CVE-2024-37054HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling ...
CVE-2024-37053HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ...
CVE-2024-37052HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ...
CVE-2024-5000HIGH7.5An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS produ...
CVE-2024-5422HIGH7.1An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnse...
CVE-2024-5421HIGH8.7Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-int...
CVE-2024-5420HIGH8.3Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec...
CVE-2024-20887HIGH7.5Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary ...
CVE-2024-20884HIGH7.8Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Re...
CVE-2024-20883HIGH7.8Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-20...
CVE-2024-20879HIGH7.1Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write...
CVE-2024-20878HIGH7.8Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows loc...
CVE-2024-20877HIGH7.8Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allo...
CVE-2024-20876HIGH7.8Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to mem...
CVE-2024-20874HIGH7.8Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch...
CVE-2024-4856HIGH8.2The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back...
CVE-2024-4749HIGH8.3The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now