2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37137 | MEDIUM | 5.5 | 0.1% | Jun 28, 2024 | Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnera... |
| CVE-2024-5642 | MEDIUM | 6.5 | 0.7% | Jun 27, 2024 | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an... |
| CVE-2024-39209 | MEDIUM | 6.3 | 1.0% | Jun 27, 2024 | luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter. |
| CVE-2024-39132 | MEDIUM | 6.5 | 0.4% | Jun 27, 2024 | A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the ... |
| CVE-2024-36755 | MEDIUM | 6.8 | 0.1% | Jun 27, 2024 | D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downlo... |
| CVE-2024-36075 | MEDIUM | 6.5 | 0.5% | Jun 27, 2024 | The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution... |
| CVE-2024-22276 | MEDIUM | 5.3 | 0.2% | Jun 27, 2024 | VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicio... |
| CVE-2024-22272 | MEDIUM | 4.9 | 0.4% | Jun 27, 2024 | VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator ... |
| CVE-2024-22260 | MEDIUM | 6.8 | 0.4% | Jun 27, 2024 | VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access ... |
| CVE-2024-39133 | MEDIUM | 4.3 | 0.5% | Jun 27, 2024 | Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_pars... |
| CVE-2024-39129 | MEDIUM | 5.3 | 0.4% | Jun 27, 2024 | Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the functi... |
| CVE-2024-31802 | MEDIUM | 6.3 | 0.3% | Jun 27, 2024 | DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code. |
| CVE-2024-6086 | MEDIUM | 4.3 | 0.4% | Jun 27, 2024 | In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organi... |
| CVE-2024-5936 | MEDIUM | 6.1 | 28.9% | Jun 27, 2024 | An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' param... |
| CVE-2024-5935 | MEDIUM | 5.4 | 0.2% | Jun 27, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete ... |
| CVE-2024-5933 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest versi... |
| CVE-2024-5755 | MEDIUM | 5.3 | 0.3% | Jun 27, 2024 | In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the em... |
| CVE-2024-5714 | MEDIUM | 6.8 | 0.5% | Jun 27, 2024 | In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissi... |
| CVE-2024-5710 | MEDIUM | 6.5 | 0.4% | Jun 27, 2024 | berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vuln... |
| CVE-2024-3331 | MEDIUM | 6.8 | 0.4% | Jun 27, 2024 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spo... |
| CVE-2024-3017 | MEDIUM | 6.5 | 0.3% | Jun 27, 2024 | In a Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (... |
| CVE-2024-35153 | MEDIUM | 4.8 | 0.4% | Jun 27, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg... |
| CVE-2024-6388 | MEDIUM | 5.5 | 0.1% | Jun 27, 2024 | Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil... |
| CVE-2024-31883 | MEDIUM | 5.9 | 0.6% | Jun 27, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attac... |
| CVE-2024-28820 | MEDIUM | 6.3 | 0.4% | Jun 27, 2024 | Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now