2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-51727HIGH7.5Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to inval...
CVE-2024-42494HIGH7.5Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or ...
CVE-2024-11220HIGH7.8A local low-level user on the server machine with credentials to the running OAS services can create and execute a repor...
CVE-2024-54749HIGH7.5Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke...
CVE-2024-53691HIGH8.8A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2024-50404HIGH8.8A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re...
CVE-2024-50403HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50402HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-48868HIGH7.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-48867HIGH7.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o...
CVE-2024-48865HIGH7.5An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If ...
CVE-2024-54137HIGH7.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co...
CVE-2024-54135HIGH8.8ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are v...
CVE-2024-12254HIGH8.7Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa...
CVE-2024-54141HIGH7.5phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, p...
CVE-2024-11738HIGH7.5A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente...
CVE-2024-54216HIGH7.7Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForm...
CVE-2024-54209HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome ...
CVE-2024-54208HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block ...
CVE-2024-54205HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery...
CVE-2024-53825HIGH7.2Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Cont...
CVE-2024-53824HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-53821HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Pie Regis...
CVE-2024-53817HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Product La...
CVE-2024-53815HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now