2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36027 | HIGH | 7.1 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: do not flag ZEROOUT on non-dirty exte... |
| CVE-2024-35430 | HIGH | 8.1 | 0.6% | May 30, 2024 | In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks whil... |
| CVE-2024-36019 | HIGH | 7.1 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: regmap: maple: Fix cache corruption in regcache_map... |
| CVE-2024-3584 | HIGH | 7.5 | 0.6% | May 30, 2024 | qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{n... |
| CVE-2024-5326 | HIGH | 8.8 | 1.4% | May 30, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized modi... |
| CVE-2024-5207 | HIGH | 7.2 | 0.5% | May 30, 2024 | The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for W... |
| CVE-2024-36267 | HIGH | 8.1 | 0.5% | May 30, 2024 | Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, ... |
| CVE-2024-36114 | HIGH | 8.6 | 0.5% | May 29, 2024 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr... |
| CVE-2024-35492 | HIGH | 7.5 | 0.5% | May 29, 2024 | Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c.... |
| CVE-2024-36016 | HIGH | 7.8 | 0.3% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_rece... |
| CVE-2024-35434 | HIGH | 7.5 | 0.6% | May 29, 2024 | Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/... |
| CVE-2024-36427 | HIGH | 8.1 | 0.5% | May 29, 2024 | The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authent... |
| CVE-2024-35333 | HIGH | 8.4 | 0.4% | May 29, 2024 | A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occ... |
| CVE-2024-36378 | HIGH | 7.5 | 0.4% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens |
| CVE-2024-36377 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions |
| CVE-2024-36376 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their p... |
| CVE-2024-36365 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate... |
| CVE-2024-5185 | HIGH | 8.3 | 0.2% | May 29, 2024 | The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result... |
| CVE-2024-25977 | HIGH | 7.3 | 0.6% | May 29, 2024 | The application does not change the session token when using the login or logout functionality. An attacker can set a se... |
| CVE-2024-28826 | HIGH | 8.1 | 0.5% | May 29, 2024 | Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and... |
| CVE-2024-36015 | HIGH | 7.8 | 0.3% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In re... |
| CVE-2024-4611 | HIGH | 8.1 | 0.5% | May 29, 2024 | The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_valu... |
| CVE-2024-21512 | HIGH | 8.2 | 3.1% | May 29, 2024 | Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitizatio... |
| CVE-2024-5204 | HIGH | 8.8 | 0.6% | May 29, 2024 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1... |
| CVE-2024-35226 | HIGH | 7.3 | 0.5% | May 28, 2024 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now