2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4163 | HIGH | 8 | 0.4% | Apr 26, 2024 | The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovere... |
| CVE-2024-31755 | HIGH | 7.6 | 0.6% | Apr 26, 2024 | cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of func... |
| CVE-2024-33673 | HIGH | 7.8 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacki... |
| CVE-2024-33672 | HIGH | 7.1 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to... |
| CVE-2024-33671 | HIGH | 7.1 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded S... |
| CVE-2024-33666 | HIGH | 8.6 | 0.5% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounti... |
| CVE-2024-32868 | HIGH | 8.1 | 0.5% | Apr 26, 2024 | ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SM... |
| CVE-2024-31609 | HIGH | 7.1 | 0.4% | Apr 25, 2024 | Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and... |
| CVE-2024-32324 | HIGH | 7.8 | 0.3% | Apr 25, 2024 | Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to exe... |
| CVE-2024-3625 | HIGH | 7.3 | 0.3% | Apr 25, 2024 | A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. ... |
| CVE-2024-3624 | HIGH | 7.3 | 0.3% | Apr 25, 2024 | A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This... |
| CVE-2024-3622 | HIGH | 8.8 | 0.5% | Apr 25, 2024 | A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text for... |
| CVE-2024-32358 | HIGH | 7.5 | 0.7% | Apr 25, 2024 | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in... |
| CVE-2024-28241 | HIGH | 7.8 | 0.2% | Apr 25, 2024 | The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DL... |
| CVE-2024-28240 | HIGH | 7.8 | 0.2% | Apr 25, 2024 | The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI ... |
| CVE-2024-1657 | HIGH | 8.1 | 0.4% | Apr 25, 2024 | A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation fro... |
| CVE-2024-1139 | HIGH | 7.7 | 0.9% | Apr 25, 2024 | A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote att... |
| CVE-2024-4171 | HIGH | 8.8 | 1.4% | Apr 25, 2024 | A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHan... |
| CVE-2024-4024 | HIGH | 8.8 | 14.9% | Apr 25, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starti... |
| CVE-2024-4170 | HIGH | 8.8 | 1.7% | Apr 25, 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429... |
| CVE-2024-4169 | HIGH | 8.8 | 1.8% | Apr 25, 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the funct... |
| CVE-2024-33247 | HIGH | 8.8 | 0.7% | Apr 25, 2024 | Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php. |
| CVE-2024-25026 | HIGH | 7.5 | 0.8% | Apr 25, 2024 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vul... |
| CVE-2024-4168 | HIGH | 8.8 | 1.8% | Apr 25, 2024 | A vulnerability was found in Tenda 4G300 1.01.42. It has been classified as critical. This affects the function sub_4260... |
| CVE-2024-4167 | HIGH | 8.8 | 1.8% | Apr 25, 2024 | A vulnerability was found in Tenda 4G300 1.01.42 and classified as critical. Affected by this issue is the function sub_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now