2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38524HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa...
CVE-2024-34711HIGH8.2GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne...
CVE-2024-29198HIGH8.2GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss...
CVE-2024-13090HIGH7.3A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure...
CVE-2024-13089HIGH7.5An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut...
CVE-2024-13088HIGH7.8An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t...
CVE-2024-31127HIGH7.3An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t...
CVE-2024-54189HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-52561HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-36486HIGH7.8A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto...
CVE-2024-53026HIGH8.2Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021HIGH8.2Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020HIGH8.2Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53019HIGH8.2Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so...
CVE-2024-53010HIGH7.8Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-57459HIGH7.3A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds ...
CVE-2024-54028HIGH7.8An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra...
CVE-2024-52035HIGH7.8An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. ...
CVE-2024-48877HIGH7.8A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers...
CVE-2024-57783HIGH8.1The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu...
CVE-2024-12168HIGH7.8Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-11857HIGH8.5Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat...
CVE-2024-13917HIGH8.3An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-12224HIGH8.8Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create...
CVE-2024-54952HIGH7.5MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now