2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37137MEDIUM5.5Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnera...
CVE-2024-5642MEDIUM6.5CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an...
CVE-2024-39209MEDIUM6.3luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
CVE-2024-39132MEDIUM6.5A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the ...
CVE-2024-36755MEDIUM6.8D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downlo...
CVE-2024-36075MEDIUM6.5The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution...
CVE-2024-22276MEDIUM5.3VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicio...
CVE-2024-22272MEDIUM4.9VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator ...
CVE-2024-22260MEDIUM6.8VMware Workspace One UEM update addresses an information exposure vulnerability.  A malicious actor with network access ...
CVE-2024-39133MEDIUM4.3Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_pars...
CVE-2024-39129MEDIUM5.3Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the functi...
CVE-2024-31802MEDIUM6.3DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.
CVE-2024-6086MEDIUM4.3In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organi...
CVE-2024-5936MEDIUM6.1An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' param...
CVE-2024-5935MEDIUM5.4A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete ...
CVE-2024-5933MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest versi...
CVE-2024-5755MEDIUM5.3In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the em...
CVE-2024-5714MEDIUM6.8In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissi...
CVE-2024-5710MEDIUM6.5berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vuln...
CVE-2024-3331MEDIUM6.8Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spo...
CVE-2024-3017MEDIUM6.5In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (...
CVE-2024-35153MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg...
CVE-2024-6388MEDIUM5.5Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil...
CVE-2024-31883MEDIUM5.9IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attac...
CVE-2024-28820MEDIUM6.3Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now