2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28287 | HIGH | 7.3 | 0.4% | Apr 2, 2024 | A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect use... |
| CVE-2024-22248 | HIGH | 7.1 | 0.4% | Apr 2, 2024 | VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim ... |
| CVE-2024-22246 | HIGH | 7.4 | 0.4% | Apr 2, 2024 | VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execut... |
| CVE-2024-30248 | HIGH | 7.7 | 0.5% | Apr 2, 2024 | Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel... |
| CVE-2024-30965 | HIGH | 8.8 | 0.4% | Apr 2, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php... |
| CVE-2024-29514 | HIGH | 8.8 | 1.3% | Apr 2, 2024 | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload... |
| CVE-2024-29949 | HIGH | 7.2 | 1.3% | Apr 2, 2024 | There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administr... |
| CVE-2024-31005 | HIGH | 8.1 | 1.2% | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_Mdhd... |
| CVE-2024-31003 | HIGH | 8.8 | 1.5% | Apr 2, 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4... |
| CVE-2024-29074 | HIGH | 8.8 | 0.2% | Apr 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper in... |
| CVE-2024-28951 | HIGH | 7.8 | 0.2% | Apr 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u... |
| CVE-2024-28226 | HIGH | 7.5 | 0.6% | Apr 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input. |
| CVE-2024-26674 | HIGH | 7.1 | 0.3% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_... |
| CVE-2024-26673 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol ... |
| CVE-2024-26672 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced b... |
| CVE-2024-26669 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When... |
| CVE-2024-26666 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix RCU use in TDLS fast-xmit This... |
| CVE-2024-26665 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv... |
| CVE-2024-26664 | HIGH | 7.1 | 0.2% | Apr 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access ... |
| CVE-2024-24581 | HIGH | 7.8 | 0.2% | Apr 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write. |
| CVE-2024-22098 | HIGH | 8.8 | 0.2% | Apr 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after f... |
| CVE-2024-22092 | HIGH | 7.4 | 0.4% | Apr 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, althoug... |
| CVE-2024-25187 | HIGH | 8.6 | 0.7% | Apr 2, 2024 | Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sens... |
| CVE-2024-20849 | HIGH | 7.8 | 0.2% | Apr 2, 2024 | Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 all... |
| CVE-2024-20848 | HIGH | 7.8 | 0.2% | Apr 2, 2024 | Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now