2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37157MEDIUM5.3Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o...
CVE-2024-36122MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o...
CVE-2024-34750HIGH7.5Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When proc...
CVE-2024-6488Rejected reason: This is REJECTED.
CVE-2024-36113MEDIUM6.5Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t...
CVE-2024-35234MEDIUM6.1Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o...
CVE-2024-33871HIGH8.8An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution v...
CVE-2024-33870MEDIUM6.3An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript documen...
CVE-2024-33869MEDIUM5.3An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a cra...
CVE-2024-29511HIGH7.5Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrar...
CVE-2024-29510MEDIUM6.3Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with ...
CVE-2024-29507MEDIUM5.4Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont p...
CVE-2024-5887Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5821MEDIUM6.2The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file ...
CVE-2024-35227HIGH7.5Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o...
CVE-2024-31223MEDIUM5.3Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env...
CVE-2024-29509HIGH8.8Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the ...
CVE-2024-29508LOW3.3Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in th...
CVE-2024-29506HIGH8.8Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF ...
CVE-2024-3332MEDIUM6.5A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
CVE-2024-39844CRITICAL9.8In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
CVE-2024-39248MEDIUM5.4A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-6126LOW3.2A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pa...
CVE-2024-6052MEDIUM5.4Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scr...
CVE-2024-39223CRITICAL9.8An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now