2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36461 | HIGH | 8.8 | 0.8% | Aug 12, 2024 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. |
| CVE-2024-36460 | HIGH | 8.1 | 0.6% | Aug 12, 2024 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te... |
| CVE-2024-36035 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec... |
| CVE-2024-36034 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report... |
| CVE-2024-32765 | MEDIUM | 4.2 | 0.2% | Aug 12, 2024 | A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local ... |
| CVE-2024-30188 | HIGH | 8.1 | 6.0% | Aug 12, 2024 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional reso... |
| CVE-2024-29831 | HIGH | 8.8 | 1.2% | Aug 12, 2024 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox... |
| CVE-2024-29082 | HIGH | 8.6 | 0.8% | Aug 12, 2024 | Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa... |
| CVE-2024-22123 | LOW | 2.7 | 0.6% | Aug 12, 2024 | Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file fo... |
| CVE-2024-22122 | CRITICAL | 9.1 | 1.6% | Aug 12, 2024 | Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat... |
| CVE-2024-22121 | MEDIUM | 6.1 | 0.2% | Aug 12, 2024 | A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integri... |
| CVE-2024-22116 | HIGH | 7.2 | 1.6% | Aug 12, 2024 | An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ... |
| CVE-2024-22114 | MEDIUM | 4.3 | 0.6% | Aug 12, 2024 | User with no permission to any of the Hosts can access and view host count & other statistics through System Information... |
| CVE-2024-21881 | HIGH | 8.6 | 0.3% | Aug 12, 2024 | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp... |
| CVE-2024-21880 | HIGH | 7.2 | 2.3% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ... |
| CVE-2024-21879 | HIGH | 8.8 | 2.5% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet... |
| CVE-2024-21878 | CRITICAL | 9.8 | 1.4% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway ... |
| CVE-2024-21877 | MEDIUM | 6.5 | 0.8% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in ... |
| CVE-2024-21876 | CRITICAL | 9.1 | 0.8% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enph... |
| CVE-2024-0115 | MEDIUM | 6.1 | 0.2% | Aug 12, 2024 | NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may caus... |
| CVE-2024-0113 | HIGH | 8.8 | 1.0% | Aug 12, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau... |
| CVE-2024-42493 | MEDIUM | 5.3 | 0.3% | Aug 8, 2024 | Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers an... |
| CVE-2024-42408 | LOW | 3.7 | 0.4% | Aug 8, 2024 | The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which cou... |
| CVE-2024-41161 | CRITICAL | 9.8 | 0.6% | Aug 8, 2024 | Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, so... |
| CVE-2024-39287 | HIGH | 7.5 | 0.3% | Aug 8, 2024 | Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now