2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37382HIGH7.2An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows att...
CVE-2024-0104HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us...
CVE-2024-7394MEDIUM4.8Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue a...
CVE-2024-7123Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-7121Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-42366CRITICAL9VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-per...
CVE-2024-42365HIGH8.8Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9...
CVE-2024-0108HIGH8.8NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean u...
CVE-2024-0107HIGH7.8NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use...
CVE-2024-0102MEDIUM5.5NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds...
CVE-2024-0101HIGH7.5NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter ...
CVE-2024-7480MEDIUM4.4An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interfa...
CVE-2024-7477MEDIUM6.7A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privil...
CVE-2024-41238MEDIUM5.3A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an...
CVE-2024-7490CRITICAL9.8Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause...
CVE-2024-42357CRITICAL9.8Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a s...
CVE-2024-42356HIGH7.2Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into a...
CVE-2024-42355CRITICAL9.8Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages wh...
CVE-2024-42354MEDIUM5.9Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the publi...
CVE-2024-41942HIGH7.2JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and ...
CVE-2024-7348HIGH7.5Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary...
CVE-2024-3659HIGH7.2Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen...
CVE-2024-7610MEDIUM6.5A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before...
CVE-2024-7554MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions start...
CVE-2024-5423MEDIUM6.5Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now