2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-49360HIGH8.4Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat...
CVE-2024-36623HIGH8.1moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult...
CVE-2024-49804HIGH7.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user...
CVE-2024-49803HIGH8.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr...
CVE-2024-11983HIGH7.2Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit...
CVE-2024-11982HIGH7.2Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi...
CVE-2024-11481HIGH8.2A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han...
CVE-2024-11013HIGH7.2Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,...
CVE-2024-11981HIGH7.5Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta...
CVE-2024-11980HIGH8.6Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem...
CVE-2024-48651HIGH7.5In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th...
CVE-2024-54124HIGH8.8In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
CVE-2024-11978HIGH7.5DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ...
CVE-2024-9852HIGH7.8Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-8300HIGH7Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsub...
CVE-2024-8299HIGH7.8Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-11968HIGH7.5A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulner...
CVE-2024-11969HIGH8.8The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili...
CVE-2024-11963HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected b...
CVE-2024-11961HIGH7.5A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This i...
CVE-2024-11960HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f...
CVE-2024-11959HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form...
CVE-2024-53736HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars custom-shortcode-sidebars allows...
CVE-2024-53734HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jamie O Idealien Category Enhancements idealien-category-enhancements...
CVE-2024-53733HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fenc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now