2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54359HIGH8.2Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Co...
CVE-2024-54358HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D ...
CVE-2024-54355HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.T...
CVE-2024-54353HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-...
CVE-2024-54352HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects So...
CVE-2024-54332HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allow...
CVE-2024-54331HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affe...
CVE-2024-12668HIGH8.2Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp...
CVE-2024-10972HIGH7.3Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with...
CVE-2024-12478HIGH8.8A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the ...
CVE-2024-12646HIGH8.1The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local...
CVE-2024-12644HIGH7.1The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser...
CVE-2024-12643HIGH8.1The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ...
CVE-2024-12642HIGH8.1TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca...
CVE-2024-56086HIGH7.1An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are...
CVE-2024-56084HIGH7.1An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea...
CVE-2024-53376HIGH8.8CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ...
CVE-2024-56083HIGH8.1Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly...
CVE-2024-11858HIGH7.8A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation wh...
CVE-2024-7701HIGH7.5Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption B...
CVE-2024-56073HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote...
CVE-2024-56072HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to ca...
CVE-2024-55970HIGH7.5File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the ...
CVE-2024-31892HIGH7.5IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized act...
CVE-2024-31891HIGH7.8IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulner...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now