2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1394HIGH7.5A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion ...
CVE-2024-29732CRITICAL9.8A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthent...
CVE-2024-26643MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbindi...
CVE-2024-26642MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with t...
CVE-2024-27438CRITICAL9.8Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is n...
CVE-2024-26307MEDIUM5.3Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of ...
CVE-2024-29133MEDIUM5.4Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from ...
CVE-2024-29131HIGH7.3Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from ...
CVE-2024-1148CRITICAL9.8Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files...
CVE-2024-1147CRITICAL9.8Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
CVE-2024-2754HIGH8.8A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unk...
CVE-2024-2162HIGH8.8An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on...
CVE-2024-2161CRITICAL9.8Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects K...
CVE-2024-28835MEDIUM5A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially cra...
CVE-2024-29864CRITICAL9.8Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
CVE-2024-29862HIGH7.5The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wr...
CVE-2024-29859CRITICAL9.8In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file ...
CVE-2024-29858CRITICAL9.8In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid l...
CVE-2024-28635MEDIUM6.1Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute ar...
CVE-2024-22724MEDIUM6.6An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrar...
CVE-2024-1538HIGH8.8The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-2713MEDIUM6.5A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affecte...
CVE-2024-2712MEDIUM6.5A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. Th...
CVE-2024-2167Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-2041. Reason: This candidate is a r...
CVE-2024-2054CRITICAL9.8The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now