2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3017MEDIUM6.5In a Silicon Labs  multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (...
CVE-2024-2882CRITICAL9.3SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. T...
CVE-2024-5548HIGH7.5A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-pro...
CVE-2024-5547HIGH7.5A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository,...
CVE-2024-5334HIGH7.5A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerabili...
CVE-2024-35260CRITICAL9.8An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over...
CVE-2024-35153MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg...
CVE-2024-31916HIGH7.5IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho...
CVE-2024-24792HIGH7.5Parsing a corrupt or malicious image with invalid color indices can cause a panic.
CVE-2024-6388MEDIUM5.5Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil...
CVE-2024-39669CRITICAL9.8In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent co...
CVE-2024-39376CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performin...
CVE-2024-39375CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileg...
CVE-2024-39374CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed thro...
CVE-2024-39373HIGH7.2TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings ...
CVE-2024-31883MEDIUM5.9IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attac...
CVE-2024-28820MEDIUM6.3Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP p...
CVE-2024-6374MEDIUM5.3A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This iss...
CVE-2024-39158HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mud...
CVE-2024-39157LOW3.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu...
CVE-2024-39156LOW3.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud...
CVE-2024-39155MEDIUM6.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu...
CVE-2024-39154HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud...
CVE-2024-39153MEDIUM4.7idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=d...
CVE-2024-1153MEDIUM4.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now