2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43797 | MEDIUM | 4.3 | 0.5% | Sep 2, 2024 | audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or ac... |
| CVE-2024-43792 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 o... |
| CVE-2024-42471 | HIGH | 7.5 | 3.0% | Sep 2, 2024 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch ... |
| CVE-2024-28100 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular use... |
| CVE-2024-8004 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-7939 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an ... |
| CVE-2024-7938 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x thr... |
| CVE-2024-7932 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allow... |
| CVE-2024-5148 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validat... |
| CVE-2024-38858 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts... |
| CVE-2024-38402 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption while processing IOCTL call for getting group info. |
| CVE-2024-38401 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while processing concurrent IOCTL calls. |
| CVE-2024-33060 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. |
| CVE-2024-33057 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the multi-link element Control field when common information length check is missing before ... |
| CVE-2024-33054 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. |
| CVE-2024-33052 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when user provides data for FM HCI command control operations. |
| CVE-2024-33051 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33050 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing... |
| CVE-2024-33048 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| CVE-2024-33047 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when the captureRead QDCM command is invoked from user-space. |
| CVE-2024-33045 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| CVE-2024-33043 | MEDIUM | 5.5 | 0.1% | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| CVE-2024-33042 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-33038 | HIGH | 7.8 | 0.1% | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |
| CVE-2024-33035 | HIGH | 8.4 | 0.1% | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now