2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52538HIGH8.8Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr...
CVE-2024-47977HIGH8.8Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr...
CVE-2024-10959HIGH7.3The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to a...
CVE-2024-47946HIGH7.2If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted val...
CVE-2024-28138HIGH7.3An unauthenticated attacker with network access to the affected device's web interface can execute any system command vi...
CVE-2024-21542HIGH8.6Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due ...
CVE-2024-53919HIGH7.6An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmwar...
CVE-2024-54198HIGH8.5In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function...
CVE-2024-54197HIGH7.2SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in ...
CVE-2024-55634HIGH8.1A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fr...
CVE-2024-50628HIGH8.8An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local ar...
CVE-2024-50627HIGH8.8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u...
CVE-2024-50626HIGH8.8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This...
CVE-2024-50625HIGH8An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web appl...
CVE-2024-54151HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to...
CVE-2024-54149HIGH8.4Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to ve...
CVE-2024-54938HIGH7.5A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc...
CVE-2024-54928HIGH7.2kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
CVE-2024-54927HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
CVE-2024-52586HIGH7.8eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version ...
CVE-2024-46547HIGH7.5A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized...
CVE-2024-54933HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
CVE-2024-54930HIGH7.2Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
CVE-2024-54922HIGH7.2A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote at...
CVE-2024-11608HIGH7.8A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now