2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-11998HIGH7.5A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects un...
CVE-2024-43703HIGH8.1Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads ...
CVE-2024-43702HIGH8.1Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access t...
CVE-2024-53623HIGH7.5Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa...
CVE-2024-36612HIGH7.5Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
CVE-2024-35371HIGH7.5Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient...
CVE-2024-53980HIGH7.5RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2024-53979HIGH8.2ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop...
CVE-2024-53865HIGH8.2zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "...
CVE-2024-53861HIGH7.5pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting ...
CVE-2024-53848HIGH7.1check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas...
CVE-2024-36611HIGH7.5In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad...
CVE-2024-49360HIGH8.4Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat...
CVE-2024-36623HIGH8.1moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult...
CVE-2024-49804HIGH7.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user...
CVE-2024-49803HIGH8.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr...
CVE-2024-11983HIGH7.2Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit...
CVE-2024-11982HIGH7.2Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi...
CVE-2024-11481HIGH8.2A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han...
CVE-2024-11013HIGH7.2Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,...
CVE-2024-11981HIGH7.5Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta...
CVE-2024-11980HIGH8.6Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem...
CVE-2024-48651HIGH7.5In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th...
CVE-2024-54124HIGH8.8In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
CVE-2024-11978HIGH7.5DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now