2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37157 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o... |
| CVE-2024-36122 | MEDIUM | 4.3 | 0.4% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o... |
| CVE-2024-34750 | HIGH | 7.5 | 4.6% | Jul 3, 2024 | Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When proc... |
| CVE-2024-6488 | — | — | — | Jul 3, 2024 | Rejected reason: This is REJECTED. |
| CVE-2024-36113 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t... |
| CVE-2024-35234 | MEDIUM | 6.1 | 0.3% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o... |
| CVE-2024-33871 | HIGH | 8.8 | 1.4% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution v... |
| CVE-2024-33870 | MEDIUM | 6.3 | 0.5% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript documen... |
| CVE-2024-33869 | MEDIUM | 5.3 | 0.4% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a cra... |
| CVE-2024-29511 | HIGH | 7.5 | 1.1% | Jul 3, 2024 | Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrar... |
| CVE-2024-29510 | MEDIUM | 6.3 | 28.0% | Jul 3, 2024 | Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with ... |
| CVE-2024-29507 | MEDIUM | 5.4 | 0.7% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont p... |
| CVE-2024-5887 | — | — | — | Jul 3, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5821 | MEDIUM | 6.2 | 0.2% | Jul 3, 2024 | The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file ... |
| CVE-2024-35227 | HIGH | 7.5 | 0.6% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o... |
| CVE-2024-31223 | MEDIUM | 5.3 | 1.1% | Jul 3, 2024 | Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env... |
| CVE-2024-29509 | HIGH | 8.8 | 1.4% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the ... |
| CVE-2024-29508 | LOW | 3.3 | 0.4% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th... |
| CVE-2024-29506 | HIGH | 8.8 | 0.9% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF ... |
| CVE-2024-3332 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device |
| CVE-2024-39844 | CRITICAL | 9.8 | 3.9% | Jul 3, 2024 | In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. |
| CVE-2024-39248 | MEDIUM | 5.4 | 0.7% | Jul 3, 2024 | A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-6126 | LOW | 3.2 | 0.3% | Jul 3, 2024 | A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa... |
| CVE-2024-6052 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scr... |
| CVE-2024-39223 | CRITICAL | 9.8 | 0.7% | Jul 3, 2024 | An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now