2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37062 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e... |
| CVE-2024-37061 | HIGH | 8.8 | 0.9% | Jun 4, 2024 | Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a malicious... |
| CVE-2024-37060 | HIGH | 8.8 | 0.8% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling... |
| CVE-2024-37059 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling ... |
| CVE-2024-37058 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling ... |
| CVE-2024-37057 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabli... |
| CVE-2024-37056 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling... |
| CVE-2024-37055 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling... |
| CVE-2024-37054 | HIGH | 8.8 | 0.7% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling ... |
| CVE-2024-37053 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ... |
| CVE-2024-37052 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling ... |
| CVE-2024-5000 | HIGH | 7.5 | 0.6% | Jun 4, 2024 | An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS produ... |
| CVE-2024-5422 | HIGH | 7.1 | 0.7% | Jun 4, 2024 | An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnse... |
| CVE-2024-5421 | HIGH | 8.7 | 3.7% | Jun 4, 2024 | Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-int... |
| CVE-2024-5420 | HIGH | 8.3 | 5.5% | Jun 4, 2024 | Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec... |
| CVE-2024-20887 | HIGH | 7.5 | 0.3% | Jun 4, 2024 | Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary ... |
| CVE-2024-20884 | HIGH | 7.8 | 0.1% | Jun 4, 2024 | Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Re... |
| CVE-2024-20883 | HIGH | 7.8 | 0.1% | Jun 4, 2024 | Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-20... |
| CVE-2024-20879 | HIGH | 7.1 | 0.1% | Jun 4, 2024 | Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write... |
| CVE-2024-20878 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows loc... |
| CVE-2024-20877 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allo... |
| CVE-2024-20876 | HIGH | 7.8 | 0.1% | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to mem... |
| CVE-2024-20874 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch... |
| CVE-2024-4856 | HIGH | 8.2 | 0.5% | Jun 4, 2024 | The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-4749 | HIGH | 8.3 | 0.4% | Jun 4, 2024 | The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now