2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37371CRITICAL9.1In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling...
CVE-2024-39828MEDIUM6.1R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to ...
CVE-2024-38533MEDIUM6.5ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access...
CVE-2024-38532HIGH7.1The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cry...
CVE-2024-38525HIGH7.5dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malforme...
CVE-2024-37370HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS...
CVE-2024-39307LOW3.5Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside...
CVE-2024-39302LOW3.7BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be...
CVE-2024-38518MEDIUM4.6BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a...
CVE-2024-29040MEDIUM4.3This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Q...
CVE-2024-5827CRITICAL9.8Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can injec...
CVE-2024-5712HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the late...
CVE-2024-3995LOW2In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
CVE-2024-38528HIGH7.5nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing li...
CVE-2024-5972Rejected reason: CVE ID issued in error. This is not a valid vulnerability.
CVE-2024-38514HIGH7.4NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lac...
CVE-2024-38322HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp...
CVE-2024-35156MEDIUM6.5IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error ...
CVE-2024-35116HIGH7.5IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error app...
CVE-2024-27629HIGH7.8An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name ...
CVE-2024-27628HIGH8.1Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method...
CVE-2024-25053MEDIUM5.9IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certif...
CVE-2024-25041MEDIUM5.4IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cro...
CVE-2024-25031MEDIUM6.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allo...
CVE-2024-38374HIGH7.5The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now