2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6717 | HIGH | 8.6 | 0.4% | Jul 23, 2024 | HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to p... |
| CVE-2024-24507 | MEDIUM | 6.1 | 0.4% | Jul 22, 2024 | Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser par... |
| CVE-2024-6913 | HIGH | 8.8 | 1.4% | Jul 22, 2024 | Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windo... |
| CVE-2024-6912 | CRITICAL | 9.8 | 1.1% | Jul 22, 2024 | Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all pron... |
| CVE-2024-6911 | HIGH | 7.5 | 4.9% | Jul 22, 2024 | Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P... |
| CVE-2024-6806 | CRITICAL | 9.8 | 1.0% | Jul 22, 2024 | The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These miss... |
| CVE-2024-6805 | CRITICAL | 9.8 | 1.0% | Jul 22, 2024 | The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. Thes... |
| CVE-2024-6794 | CRITICAL | 9.8 | 1.2% | Jul 22, 2024 | A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in r... |
| CVE-2024-6793 | CRITICAL | 9.8 | 1.2% | Jul 22, 2024 | A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote c... |
| CVE-2024-6791 | HIGH | 7.8 | 0.5% | Jul 22, 2024 | A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote co... |
| CVE-2024-40502 | CRITICAL | 9.8 | 1.3% | Jul 22, 2024 | SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute ar... |
| CVE-2024-6675 | HIGH | 7.8 | 0.4% | Jul 22, 2024 | A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Succ... |
| CVE-2024-6638 | MEDIUM | 5.5 | 0.2% | Jul 22, 2024 | An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an i... |
| CVE-2024-6122 | MEDIUM | 5.5 | 0.2% | Jul 22, 2024 | An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r... |
| CVE-2024-6121 | HIGH | 7.8 | 0.3% | Jul 22, 2024 | An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including ... |
| CVE-2024-39250 | CRITICAL | 9.8 | 4.9% | Jul 22, 2024 | EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t... |
| CVE-2024-34329 | HIGH | 8.4 | 0.6% | Jul 22, 2024 | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch al... |
| CVE-2024-41880 | MEDIUM | 5.3 | 0.3% | Jul 22, 2024 | In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effective... |
| CVE-2024-40075 | MEDIUM | 4.3 | 0.5% | Jul 22, 2024 | Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability. |
| CVE-2024-38944 | CRITICAL | 9.8 | 2.4% | Jul 22, 2024 | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-37380 | MEDIUM | 5.3 | 0.2% | Jul 22, 2024 | A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+... |
| CVE-2024-41130 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_fr... |
| CVE-2024-40634 | HIGH | 7.5 | 1.4% | Jul 22, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i... |
| CVE-2024-40051 | HIGH | 7.5 | 0.7% | Jul 22, 2024 | IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter. |
| CVE-2024-28698 | CRITICAL | 9.8 | 1.5% | Jul 22, 2024 | Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now