2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43334HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom...
CVE-2024-35164HIGH7.5The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers...
CVE-2024-13451HIGH7.5The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-49365HIGH8.1tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can...
CVE-2024-49364HIGH8.1tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing ...
CVE-2024-46992HIGH7.8Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro...
CVE-2024-53621HIGH7.5A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow...
CVE-2024-8419HIGH7.5The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the ...
CVE-2024-24915HIGH7.2Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ...
CVE-2024-52928HIGH8.3Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi...
CVE-2024-6174HIGH8.8When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven...
CVE-2024-27685HIGH7.1SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi...
CVE-2024-51983HIGH7.5An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ...
CVE-2024-51982HIGH7.5An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr...
CVE-2024-51979HIGH7.2An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP...
CVE-2024-56917HIGH7.1Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
CVE-2024-4994HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr...
CVE-2024-4025HIGH7.5A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16...
CVE-2024-7586HIGH7.5An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior...
CVE-2024-24916HIGH7.8Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ...
CVE-2024-38824HIGH7.5Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory...
CVE-2024-7562HIGH7.3A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In...
CVE-2024-9062HIGH7.8The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its...
CVE-2024-7457HIGH7.8The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod...
CVE-2024-43706HIGH8.8Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now