2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29417 | HIGH | 8.4 | 0.2% | May 3, 2024 | Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges ... |
| CVE-2024-1067 | HIGH | 7.4 | 0.2% | May 3, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2024-33787 | HIGH | 8.2 | 0.4% | May 3, 2024 | Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerab... |
| CVE-2024-4461 | HIGH | 7.8 | 0.2% | May 3, 2024 | Unquoted path or search item vulnerability in SugarSync versions prior to 4.1.3 for Windows. This misconfiguration could... |
| CVE-2024-34073 | HIGH | 7.8 | 1.1% | May 3, 2024 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected ve... |
| CVE-2024-34072 | HIGH | 7.8 | 0.4% | May 3, 2024 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.... |
| CVE-2024-33921 | HIGH | 8.8 | 0.4% | May 3, 2024 | Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21. |
| CVE-2024-33924 | HIGH | 7.1 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna ... |
| CVE-2024-32810 | HIGH | 7.6 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: fr... |
| CVE-2024-33946 | HIGH | 7.1 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPify s.R.O. WPify... |
| CVE-2024-34402 | HIGH | 8.6 | 1.2% | May 3, 2024 | An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long ke... |
| CVE-2024-34033 | HIGH | 8.8 | 1.0% | May 3, 2024 | Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal atta... |
| CVE-2024-34032 | HIGH | 8.8 | 8.7% | May 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoin... |
| CVE-2024-34031 | HIGH | 8.8 | 0.5% | May 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx... |
| CVE-2024-30306 | HIGH | 7.8 | 0.5% | May 2, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability when ... |
| CVE-2024-30305 | HIGH | 7.8 | 0.6% | May 2, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-30304 | HIGH | 7.8 | 0.6% | May 2, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-30303 | HIGH | 7.8 | 0.5% | May 2, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-30301 | HIGH | 7.8 | 0.6% | May 2, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-25047 | HIGH | 8.6 | 0.6% | May 2, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.2 is vulnerable to injection attacks in application l... |
| CVE-2024-4140 | HIGH | 7.5 | 1.1% | May 2, 2024 | An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service wh... |
| CVE-2024-34394 | HIGH | 8.1 | 1.0% | May 2, 2024 | libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namesp... |
| CVE-2024-34393 | HIGH | 8.1 | 1.0% | May 2, 2024 | libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function... |
| CVE-2024-33396 | HIGH | 8.4 | 0.2% | May 2, 2024 | An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command... |
| CVE-2024-4215 | HIGH | 8.8 | 0.6% | May 2, 2024 | pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now