2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3017 | MEDIUM | 6.5 | 0.3% | Jun 27, 2024 | In a Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (... |
| CVE-2024-2882 | CRITICAL | 9.3 | 0.7% | Jun 27, 2024 | SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. T... |
| CVE-2024-5548 | HIGH | 7.5 | 1.0% | Jun 27, 2024 | A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-pro... |
| CVE-2024-5547 | HIGH | 7.5 | 1.0% | Jun 27, 2024 | A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository,... |
| CVE-2024-5334 | HIGH | 7.5 | 2.1% | Jun 27, 2024 | A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerabili... |
| CVE-2024-35260 | CRITICAL | 9.8 | 1.0% | Jun 27, 2024 | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over... |
| CVE-2024-35153 | MEDIUM | 4.8 | 0.4% | Jun 27, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg... |
| CVE-2024-31916 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho... |
| CVE-2024-24792 | HIGH | 7.5 | 0.7% | Jun 27, 2024 | Parsing a corrupt or malicious image with invalid color indices can cause a panic. |
| CVE-2024-6388 | MEDIUM | 5.5 | 0.1% | Jun 27, 2024 | Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivil... |
| CVE-2024-39669 | CRITICAL | 9.8 | 0.8% | Jun 27, 2024 | In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent co... |
| CVE-2024-39376 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performin... |
| CVE-2024-39375 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileg... |
| CVE-2024-39374 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed thro... |
| CVE-2024-39373 | HIGH | 7.2 | 1.2% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings ... |
| CVE-2024-31883 | MEDIUM | 5.9 | 0.6% | Jun 27, 2024 | IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attac... |
| CVE-2024-28820 | MEDIUM | 6.3 | 0.4% | Jun 27, 2024 | Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP p... |
| CVE-2024-6374 | MEDIUM | 5.3 | 0.3% | Jun 27, 2024 | A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This iss... |
| CVE-2024-39158 | HIGH | 8.8 | 0.3% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mud... |
| CVE-2024-39157 | LOW | 3.8 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu... |
| CVE-2024-39156 | LOW | 3.8 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud... |
| CVE-2024-39155 | MEDIUM | 6.8 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu... |
| CVE-2024-39154 | HIGH | 8.8 | 0.3% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud... |
| CVE-2024-39153 | MEDIUM | 4.7 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=d... |
| CVE-2024-1153 | MEDIUM | 4.6 | 0.3% | Jun 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now