2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12925HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. ...
CVE-2024-32589HIGH7.1Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ...
CVE-2024-46917HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur...
CVE-2024-46916HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys...
CVE-2024-13986HIGH8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an...
CVE-2024-58240HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ...
CVE-2024-13807HIGH7.5The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-13982HIGH8.7SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar...
CVE-2024-37777HIGH8.8O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
CVE-2024-47853HIGH8.8An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w...
CVE-2024-48988HIGH7.6SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users...
CVE-2024-53494HIGH7.5Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone...
CVE-2024-56179HIGH7.8In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim...
CVE-2024-50641HIGH8.1An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera...
CVE-2024-57152HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit...
CVE-2024-53495HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon...
CVE-2024-57491HIGH8.8Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac...
CVE-2024-49827HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv...
CVE-2024-12612HIGH7.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac...
CVE-2024-53946HIGH8.8The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface....
CVE-2024-53945HIGH8.8The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe...
CVE-2024-7402HIGH7Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamp...
CVE-2024-5477HIGH7.3A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escala...
CVE-2024-26009HIGH8.1An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6....
CVE-2024-54678HIGH8.6A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now