2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39708 | HIGH | 7 | 0.2% | Jun 28, 2024 | An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096... |
| CVE-2024-6071 | CRITICAL | 10 | 1.1% | Jun 27, 2024 | PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to... |
| CVE-2024-4395 | HIGH | 7.8 | 0.2% | Jun 27, 2024 | The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local... |
| CVE-2024-39705 | CRITICAL | 9.8 | 1.3% | Jun 27, 2024 | NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data ... |
| CVE-2024-36059 | CRITICAL | 9.4 | 0.7% | Jun 27, 2024 | Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers t... |
| CVE-2024-5642 | MEDIUM | 6.5 | 0.7% | Jun 27, 2024 | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an... |
| CVE-2024-39209 | MEDIUM | 6.3 | 1.0% | Jun 27, 2024 | luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter. |
| CVE-2024-39134 | HIGH | 7.5 | 0.6% | Jun 27, 2024 | A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_f... |
| CVE-2024-39132 | MEDIUM | 6.5 | 0.4% | Jun 27, 2024 | A NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the ... |
| CVE-2024-36755 | MEDIUM | 6.8 | 0.1% | Jun 27, 2024 | D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downlo... |
| CVE-2024-36075 | MEDIUM | 6.5 | 0.5% | Jun 27, 2024 | The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution... |
| CVE-2024-36074 | HIGH | 7.2 | 0.8% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-36073 | HIGH | 7.2 | 0.8% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-36072 | CRITICAL | 9.8 | 1.0% | Jun 27, 2024 | Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera... |
| CVE-2024-2973 | CRITICAL | 10 | 1.1% | Jun 27, 2024 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or co... |
| CVE-2024-22276 | MEDIUM | 5.3 | 0.2% | Jun 27, 2024 | VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicio... |
| CVE-2024-22272 | MEDIUM | 4.9 | 0.4% | Jun 27, 2024 | VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator ... |
| CVE-2024-22260 | MEDIUM | 6.8 | 0.4% | Jun 27, 2024 | VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access ... |
| CVE-2024-6127 | CRITICAL | 9.8 | 10.3% | Jun 27, 2024 | BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote... |
| CVE-2024-39208 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials. |
| CVE-2024-39207 | HIGH | 8.2 | 0.5% | Jun 27, 2024 | lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function. |
| CVE-2024-39133 | MEDIUM | 4.3 | 0.5% | Jun 27, 2024 | Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_pars... |
| CVE-2024-39130 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the fun... |
| CVE-2024-39129 | MEDIUM | 5.3 | 0.4% | Jun 27, 2024 | Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the functi... |
| CVE-2024-38523 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authenti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now