2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6258MEDIUM6.5BT: Missing length checks of net_buf in rfcomm_handle_data
CVE-2024-5754MEDIUM6.5BT: Encryption procedure host vulnerability
CVE-2024-8782CRITICAL9.8A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete ...
CVE-2024-8281HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8280HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8279HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate...
CVE-2024-8278HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate...
CVE-2024-8059MEDIUM4.3IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
CVE-2024-7756MEDIUM6.8A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to e...
CVE-2024-4550MEDIUM6.7A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could a...
CVE-2024-45105MEDIUM6.7An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSys...
CVE-2024-45104MEDIUM6.5A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXC...
CVE-2024-45103MEDIUM4.3A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface withou...
CVE-2024-45101MEDIUM6.8A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to...
CVE-2024-3100MEDIUM6.7A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacke...
CVE-2024-39926MEDIUM5.4An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to th...
CVE-2024-39925MEDIUM6.5An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who l...
CVE-2024-39924HIGH8.8An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authen...
CVE-2024-6867MEDIUM6.5An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endp...
CVE-2024-6862HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive COR...
CVE-2024-6582MEDIUM4.3A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user...
CVE-2024-6087MEDIUM6.5An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. T...
CVE-2024-45368HIGH8.8The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response pro...
CVE-2024-43099HIGH8.8The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions bet...
CVE-2024-31416MEDIUM6.5The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the too...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now