2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26026 | HIGH | 7.5 | 7.2% | May 8, 2024 | An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have ... |
| CVE-2024-25560 | HIGH | 7.5 | 0.5% | May 8, 2024 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM)... |
| CVE-2024-25526 | HIGH | 8.1 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /Proje... |
| CVE-2024-25515 | HIGH | 7.3 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-21793 | HIGH | 7.5 | 7.1% | May 8, 2024 | An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which hav... |
| CVE-2024-31270 | HIGH | 8 | 0.4% | May 8, 2024 | Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: ... |
| CVE-2024-24833 | HIGH | 8.8 | 0.4% | May 8, 2024 | Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects... |
| CVE-2024-1438 | HIGH | 7.7 | 0.3% | May 8, 2024 | Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9. |
| CVE-2024-3507 | HIGH | 7.7 | 0.3% | May 8, 2024 | Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerabil... |
| CVE-2024-4438 | HIGH | 7.5 | 0.8% | May 8, 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487... |
| CVE-2024-4437 | HIGH | 7.5 | 0.8% | May 8, 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue oc... |
| CVE-2024-4436 | HIGH | 7.5 | 0.8% | May 8, 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue oc... |
| CVE-2024-22264 | HIGH | 7.2 | 0.5% | May 8, 2024 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMwar... |
| CVE-2024-2860 | HIGH | 7.8 | 0.2% | May 8, 2024 | The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authenticatio... |
| CVE-2024-2746 | HIGH | 8.8 | 0.2% | May 8, 2024 | Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary confi... |
| CVE-2024-1929 | HIGH | 8.4 | 0.3% | May 8, 2024 | Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Co... |
| CVE-2024-4030 | HIGH | 7.1 | 0.3% | May 7, 2024 | On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ... |
| CVE-2024-27273 | HIGH | 7.8 | 0.1% | May 7, 2024 | IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app... |
| CVE-2024-23713 | HIGH | 7.8 | 0.1% | May 7, 2024 | In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications se... |
| CVE-2024-23710 | HIGH | 7.8 | 0.1% | May 7, 2024 | In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary ap... |
| CVE-2024-23708 | HIGH | 7.8 | 0.3% | May 7, 2024 | In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli... |
| CVE-2024-23707 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local... |
| CVE-2024-23706 | HIGH | 7.8 | 0.1% | May 7, 2024 | In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c... |
| CVE-2024-23705 | HIGH | 7.8 | 0.3% | May 7, 2024 | In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat... |
| CVE-2024-23704 | HIGH | 7.8 | 0.1% | May 7, 2024 | In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now