2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58388HIGH7.5Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability t...
CVE-2024-58387HIGH7.5Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint th...
CVE-2024-31027MEDIUM5.4Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote att...
CVE-2024-31026CRITICAL9.8An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary...
CVE-2024-58386MEDIUM6.5ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authentica...
CVE-2024-42002HIGH8.4A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool...
CVE-2024-56344MEDIUM5.9IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain se...
CVE-2024-38639MEDIUM4.8An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the ...
CVE-2024-27123MEDIUM5.2A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t...
CVE-2024-11222MEDIUM6.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2024-58385CRITICAL9.8Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo...
CVE-2024-58384MEDIUM5.4Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return...
CVE-2024-14029HIGH7.5Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body a...
CVE-2024-58383HIGH7.3Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via ...
CVE-2024-23176MEDIUM5.4An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss...
CVE-2024-53922MEDIUM5.7An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. L...
CVE-2024-12145MEDIUM4.3The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
CVE-2024-58382HIGH7.5league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allo...
CVE-2024-58381HIGH7.5PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote...
CVE-2024-58380MEDIUM6.5PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes t...
CVE-2024-11080CRITICAL9.8The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in...
CVE-2024-7956HIGH7.6A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit...
CVE-2024-3773MEDIUM5.9The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes b...
CVE-2024-35585HIGH8.6Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
CVE-2024-7953HIGH8.7A vulnerability exists in the affected products that allows a threat actor to create a project and become the administra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now