2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52942MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated rem...
CVE-2024-52941MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated rem...
CVE-2024-11310HIGH7.5The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner...
CVE-2024-11309HIGH7.5The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner...
CVE-2024-11308MEDIUM5.5The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th...
CVE-2024-52940HIGH7.5AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi...
CVE-2024-43704HIGH8.4Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics...
CVE-2024-52926MEDIUM6.5Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
CVE-2024-52922MEDIUM6.5In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes...
CVE-2024-52921MEDIUM5.3In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.
CVE-2024-52920HIGH7.5Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA ...
CVE-2024-52919MEDIUM6.5Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ...
CVE-2024-52918MEDIUM6.5Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap...
CVE-2024-52917MEDIUM6.5Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received ...
CVE-2024-52916HIGH7.5Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h...
CVE-2024-52915HIGH7.5Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m...
CVE-2024-52914HIGH7.5In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr...
CVE-2024-52913MEDIUM5.3In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because ...
CVE-2024-52912HIGH7.5Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse...
CVE-2024-38828MEDIUM5.3Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
CVE-2024-11306MEDIUM6.9A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th...
CVE-2024-11305MEDIUM6.3A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability ...
CVE-2024-0793HIGH7.7A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking...
CVE-2024-52876HIGH7.5Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una...
CVE-2024-52872HIGH7.5In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now