2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4538 | HIGH | 7.5 | 0.5% | May 7, 2024 | IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to... |
| CVE-2024-4537 | HIGH | 7.5 | 0.7% | May 7, 2024 | IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to... |
| CVE-2024-4599 | HIGH | 7.5 | 0.7% | May 7, 2024 | Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker t... |
| CVE-2024-4582 | HIGH | 7.3 | 1.4% | May 7, 2024 | A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknow... |
| CVE-2024-3759 | HIGH | 7.8 | 0.2% | May 7, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free. |
| CVE-2024-3758 | HIGH | 7.8 | 0.2% | May 7, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer over... |
| CVE-2024-27217 | HIGH | 7.8 | 0.2% | May 7, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2024-23808 | HIGH | 7.8 | 0.2% | May 7, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2024-22472 | HIGH | 8.1 | 0.8% | May 7, 2024 | A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Re... |
| CVE-2024-20868 | HIGH | 7.1 | 0.2% | May 7, 2024 | Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung N... |
| CVE-2024-29941 | HIGH | 8 | 0.1% | May 6, 2024 | Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create ... |
| CVE-2024-30973 | HIGH | 8.8 | 0.9% | May 6, 2024 | An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code... |
| CVE-2024-34534 | HIGH | 7.3 | 0.5% | May 6, 2024 | A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.... |
| CVE-2024-34533 | HIGH | 7.3 | 0.5% | May 6, 2024 | A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x be... |
| CVE-2024-28725 | HIGH | 7.1 | 0.4% | May 6, 2024 | Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carous... |
| CVE-2024-33602 | HIGH | 7.4 | 0.4% | May 6, 2024 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache ... |
| CVE-2024-33601 | HIGH | 7.3 | 1.1% | May 6, 2024 | nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup ... |
| CVE-2024-33599 | HIGH | 8.1 | 1.3% | May 6, 2024 | nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhau... |
| CVE-2024-33570 | HIGH | 8.8 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3. |
| CVE-2024-33118 | HIGH | 7.5 | 0.2% | May 6, 2024 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.... |
| CVE-2024-3661 | HIGH | 7.6 | 4.1% | May 6, 2024 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solution... |
| CVE-2024-34412 | HIGH | 8.5 | 0.5% | May 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel Parce... |
| CVE-2024-34386 | HIGH | 7.6 | 0.5% | May 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Aut... |
| CVE-2024-34378 | HIGH | 8.6 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7. |
| CVE-2024-34369 | HIGH | 7.1 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now