2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34474 | HIGH | 7.8 | 0.3% | May 5, 2024 | Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as... |
| CVE-2024-4497 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. This vulnerability affects the ... |
| CVE-2024-4496 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. This affects the function for... |
| CVE-2024-4495 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this issue is the function... |
| CVE-2024-4494 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this vulnerability is... |
| CVE-2024-4493 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formS... |
| CVE-2024-34489 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0. |
| CVE-2024-34488 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ... |
| CVE-2024-34487 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.... |
| CVE-2024-34486 | HIGH | 7.5 | 0.6% | May 5, 2024 | OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFP... |
| CVE-2024-34483 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ... |
| CVE-2024-4492 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the fu... |
| CVE-2024-34478 | HIGH | 7.5 | 0.6% | May 5, 2024 | btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptibl... |
| CVE-2024-4491 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function fo... |
| CVE-2024-34475 | HIGH | 7.5 | 0.6% | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_... |
| CVE-2024-34469 | HIGH | 7.1 | 0.6% | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. |
| CVE-2024-3240 | HIGH | 8.8 | 0.8% | May 4, 2024 | The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 ... |
| CVE-2024-34455 | HIGH | 7.5 | 0.7% | May 3, 2024 | Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2. |
| CVE-2024-34066 | HIGH | 8.4 | 0.5% | May 3, 2024 | Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the ... |
| CVE-2024-27453 | HIGH | 8.6 | 0.7% | May 3, 2024 | In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the... |
| CVE-2024-28519 | HIGH | 7.8 | 0.2% | May 3, 2024 | A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privi... |
| CVE-2024-34447 | HIGH | 7.5 | 0.8% | May 3, 2024 | An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78,... |
| CVE-2024-33398 | HIGH | 7.5 | 0.6% | May 3, 2024 | There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allo... |
| CVE-2024-34446 | HIGH | 7.5 | 0.6% | May 3, 2024 | Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a ... |
| CVE-2024-33844 | HIGH | 7.5 | 0.7% | May 3, 2024 | The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now