2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1223MEDIUM4.8This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker...
CVE-2024-1222CRITICAL9.8This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated...
CVE-2024-1221LOW3.1This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload...
CVE-2024-25650MEDIUM5.9Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator...
CVE-2024-25228HIGH8.8Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerify...
CVE-2024-28251HIGH7.3Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's da...
CVE-2024-2242MEDIUM6.1The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter i...
CVE-2024-2079MEDIUM5.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-27703MEDIUM5.4Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do ti...
CVE-2024-28662MEDIUM5.4A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag...
CVE-2024-28193MEDIUM6.5your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to creat...
CVE-2024-28192MEDIUM5.3your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQ...
CVE-2024-28175MEDIUM5.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of...
CVE-2024-27102HIGH8.5Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions...
CVE-2024-27097MEDIUM5.3A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This...
CVE-2024-25250CRITICAL9.8SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code vi...
CVE-2024-24105HIGH7.8SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary co...
CVE-2024-22167HIGH7.9A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrar...
CVE-2024-24693MEDIUM5.5Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authentica...
CVE-2024-24692MEDIUM4.7Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user ...
CVE-2024-28194CRITICAL9.8your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSO...
CVE-2024-0801HIGH7.5A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
CVE-2024-0800HIGH8.8A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca....
CVE-2024-0799CRITICAL9.8An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui...
CVE-2024-2433LOW2.7An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only admin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now