2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27685HIGH7.1SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensi...
CVE-2024-51983HIGH7.5An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP requ...
CVE-2024-51982HIGH7.5An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will cr...
CVE-2024-51979HIGH7.2An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP...
CVE-2024-56917HIGH7.1Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
CVE-2024-4994HIGH8.1An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr...
CVE-2024-4025HIGH7.5A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16...
CVE-2024-7586HIGH7.5An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior...
CVE-2024-24916HIGH7.8Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution ...
CVE-2024-38824HIGH7.5Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory...
CVE-2024-7562HIGH7.3A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple In...
CVE-2024-9062HIGH7.8The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its...
CVE-2024-7457HIGH7.8The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization mod...
CVE-2024-43706HIGH8.8Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
CVE-2024-38524HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispa...
CVE-2024-34711HIGH8.2GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulne...
CVE-2024-29198HIGH8.2GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It poss...
CVE-2024-13090HIGH7.3A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configure...
CVE-2024-13089HIGH7.5An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut...
CVE-2024-13088HIGH7.8An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t...
CVE-2024-31127HIGH7.3An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t...
CVE-2024-54189HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-52561HIGH7.8A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b...
CVE-2024-36486HIGH7.8A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto...
CVE-2024-53026HIGH8.2Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now