2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6258 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | BT: Missing length checks of net_buf in rfcomm_handle_data |
| CVE-2024-5754 | MEDIUM | 6.5 | 0.3% | Sep 13, 2024 | BT: Encryption procedure host vulnerability |
| CVE-2024-8782 | CRITICAL | 9.8 | 0.7% | Sep 13, 2024 | A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete ... |
| CVE-2024-8281 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8280 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8279 | HIGH | 7.2 | 1.1% | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate... |
| CVE-2024-8278 | HIGH | 7.2 | 1.1% | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate... |
| CVE-2024-8059 | MEDIUM | 4.3 | 0.2% | Sep 13, 2024 | IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters. |
| CVE-2024-7756 | MEDIUM | 6.8 | 0.3% | Sep 13, 2024 | A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to e... |
| CVE-2024-4550 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could a... |
| CVE-2024-45105 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSys... |
| CVE-2024-45104 | MEDIUM | 6.5 | 0.2% | Sep 13, 2024 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXC... |
| CVE-2024-45103 | MEDIUM | 4.3 | 0.3% | Sep 13, 2024 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface withou... |
| CVE-2024-45101 | MEDIUM | 6.8 | 0.2% | Sep 13, 2024 | A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to... |
| CVE-2024-3100 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacke... |
| CVE-2024-39926 | MEDIUM | 5.4 | 0.4% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to th... |
| CVE-2024-39925 | MEDIUM | 6.5 | 0.6% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who l... |
| CVE-2024-39924 | HIGH | 8.8 | 13.1% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authen... |
| CVE-2024-6867 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endp... |
| CVE-2024-6862 | HIGH | 8.1 | 0.3% | Sep 13, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive COR... |
| CVE-2024-6582 | MEDIUM | 4.3 | 0.4% | Sep 13, 2024 | A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user... |
| CVE-2024-6087 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. T... |
| CVE-2024-45368 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response pro... |
| CVE-2024-43099 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions bet... |
| CVE-2024-31416 | MEDIUM | 6.5 | 0.3% | Sep 13, 2024 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the too... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now