2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38372 | LOW | 2 | 0.5% | Jul 8, 2024 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(... |
| CVE-2024-6580 | MEDIUM | 6.5 | 0.1% | Jul 8, 2024 | The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re... |
| CVE-2024-6227 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tr... |
| CVE-2024-6409 | HIGH | 7 | 27.9% | Jul 8, 2024 | A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacke... |
| CVE-2024-4882 | MEDIUM | 5.3 | 0.4% | Jul 8, 2024 | The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions. |
| CVE-2024-39896 | MEDIUM | 5.3 | 0.5% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combin... |
| CVE-2024-1305 | CRITICAL | 9.8 | 15.4% | Jul 8, 2024 | tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which ... |
| CVE-2024-39895 | MEDIUM | 6.5 | 0.8% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by fie... |
| CVE-2024-39701 | HIGH | 7.7 | 0.4% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly... |
| CVE-2024-39312 | MEDIUM | 5.3 | 0.3% | Jul 8, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-34702 | MEDIUM | 5.3 | 0.8% | Jul 8, 2024 | Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o... |
| CVE-2024-6564 | MEDIUM | 6.7 | 0.2% | Jul 8, 2024 | Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter befor... |
| CVE-2024-6563 | MEDIUM | 6.7 | 0.2% | Jul 8, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware all... |
| CVE-2024-39699 | MEDIUM | 5 | 0.4% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulne... |
| CVE-2024-39695 | MEDIUM | 6.5 | 0.6% | Jul 8, 2024 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2024-39203 | MEDIUM | 6.1 | 0.7% | Jul 8, 2024 | A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers t... |
| CVE-2024-39202 | HIGH | 8.8 | 1.4% | Jul 8, 2024 | D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd... |
| CVE-2024-31504 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause ... |
| CVE-2024-23562 | HIGH | 7.5 | 0.5% | Jul 8, 2024 | A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthen... |
| CVE-2024-21778 | HIGH | 7.2 | 0.9% | Jul 8, 2024 | A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realte... |
| CVE-2024-39677 | CRITICAL | 9.8 | 0.6% | Jul 8, 2024 | NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp... |
| CVE-2024-39308 | MEDIUM | 5.4 | 0.6% | Jul 8, 2024 | RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerabilit... |
| CVE-2024-25639 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize... |
| CVE-2024-4341 | MEDIUM | 6.5 | 0.3% | Jul 8, 2024 | Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows ... |
| CVE-2024-39743 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now