2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37371 | CRITICAL | 9.1 | 1.9% | Jun 28, 2024 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling... |
| CVE-2024-39828 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to ... |
| CVE-2024-38533 | MEDIUM | 6.5 | 0.3% | Jun 28, 2024 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access... |
| CVE-2024-38532 | HIGH | 7.1 | 0.2% | Jun 28, 2024 | The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cry... |
| CVE-2024-38525 | HIGH | 7.5 | 0.4% | Jun 28, 2024 | dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme... |
| CVE-2024-37370 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS... |
| CVE-2024-39307 | LOW | 3.5 | 0.5% | Jun 28, 2024 | Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside... |
| CVE-2024-39302 | LOW | 3.7 | 0.5% | Jun 28, 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be... |
| CVE-2024-38518 | MEDIUM | 4.6 | 0.3% | Jun 28, 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a... |
| CVE-2024-29040 | MEDIUM | 4.3 | 0.3% | Jun 28, 2024 | This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Q... |
| CVE-2024-5827 | CRITICAL | 9.8 | 3.5% | Jun 28, 2024 | Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can injec... |
| CVE-2024-5712 | HIGH | 8.1 | 0.3% | Jun 28, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the late... |
| CVE-2024-3995 | LOW | 2 | 0.6% | Jun 28, 2024 | In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins. |
| CVE-2024-38528 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing li... |
| CVE-2024-5972 | — | — | — | Jun 28, 2024 | Rejected reason: CVE ID issued in error. This is not a valid vulnerability. |
| CVE-2024-38514 | HIGH | 7.4 | 2.2% | Jun 28, 2024 | NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lac... |
| CVE-2024-38322 | HIGH | 7.5 | 0.4% | Jun 28, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp... |
| CVE-2024-35156 | MEDIUM | 6.5 | 0.5% | Jun 28, 2024 | IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error ... |
| CVE-2024-35116 | HIGH | 7.5 | 0.7% | Jun 28, 2024 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error app... |
| CVE-2024-27629 | HIGH | 7.8 | 0.2% | Jun 28, 2024 | An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name ... |
| CVE-2024-27628 | HIGH | 8.1 | 0.7% | Jun 28, 2024 | Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method... |
| CVE-2024-25053 | MEDIUM | 5.9 | 0.3% | Jun 28, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certif... |
| CVE-2024-25041 | MEDIUM | 5.4 | 0.4% | Jun 28, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cro... |
| CVE-2024-25031 | MEDIUM | 6.5 | 0.2% | Jun 28, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allo... |
| CVE-2024-38374 | HIGH | 7.5 | 0.6% | Jun 28, 2024 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now