2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22641 | HIGH | 7.5 | 1.1% | May 28, 2024 | TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG... |
| CVE-2024-28060 | HIGH | 7.3 | 0.2% | May 28, 2024 | An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arb... |
| CVE-2024-36110 | HIGH | 8.2 | 0.4% | May 28, 2024 | ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTM... |
| CVE-2024-36109 | HIGH | 7.6 | 0.4% | May 28, 2024 | CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected ve... |
| CVE-2024-33450 | HIGH | 7.5 | 0.5% | May 28, 2024 | SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information |
| CVE-2024-24919 | HIGH | 8.6 | 100.0% | May 28, 2024 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the inte... |
| CVE-2024-33402 | HIGH | 8.1 | 0.4% | May 28, 2024 | A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System ... |
| CVE-2024-35341 | HIGH | 7.5 | 0.4% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET r... |
| CVE-2024-30165 | HIGH | 7.1 | 0.2% | May 28, 2024 | Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute ... |
| CVE-2024-26024 | HIGH | 8.6 | 0.2% | May 28, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server. |
| CVE-2024-30212 | HIGH | 7 | 0.6% | May 28, 2024 | If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 ... |
| CVE-2024-24959 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24958 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24957 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24956 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24955 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24954 | HIGH | 8.2 | 0.5% | May 28, 2024 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of... |
| CVE-2024-24947 | HIGH | 8.2 | 0.8% | May 28, 2024 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of Automa... |
| CVE-2024-24946 | HIGH | 8.2 | 0.8% | May 28, 2024 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of Automa... |
| CVE-2024-24851 | HIGH | 7.5 | 1.4% | May 28, 2024 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of Automat... |
| CVE-2024-23315 | HIGH | 7.5 | 1.0% | May 28, 2024 | A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of Auto... |
| CVE-2024-4429 | HIGH | 7.4 | 0.2% | May 28, 2024 | Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensit... |
| CVE-2024-35399 | HIGH | 8.8 | 0.5% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the func... |
| CVE-2024-35397 | HIGH | 8.8 | 19.0% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHo... |
| CVE-2024-29072 | HIGH | 8.2 | 0.5% | May 28, 2024 | A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now