2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10952HIGH7.3The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJ...
CVE-2024-10587HIGH8.8The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-45207HIGH7DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the a...
CVE-2024-45205HIGH7.1An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Networ...
CVE-2024-42456HIGH8.8A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a me...
CVE-2024-42455HIGH8.1A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i...
CVE-2024-42453HIGH8.1A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected...
CVE-2024-42452HIGH8.8A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and...
CVE-2024-42449HIGH7.1From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos...
CVE-2024-40717HIGH8.8A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code exe...
CVE-2024-46624HIGH8.8An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via ...
CVE-2024-46625HIGH8.8An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0....
CVE-2024-54131HIGH7.3The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ...
CVE-2024-51772HIGH8An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti...
CVE-2024-45757HIGH7.2An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set...
CVE-2024-51771HIGH8.8A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe...
CVE-2024-51114HIGH8.8An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar...
CVE-2024-50948HIGH7.5mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s...
CVE-2024-48080HIGH7.5An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i...
CVE-2024-12053HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co...
CVE-2024-52547HIGH7.2An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit...
CVE-2024-41777HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k...
CVE-2024-41775HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ...
CVE-2024-52805HIGH7.5Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf...
CVE-2024-37302HIGH7.5Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now