2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-1867HIGH7.8G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers...
CVE-2024-52726HIGH7.5CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensiti...
CVE-2024-11618HIGH7.3A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulne...
CVE-2024-44786HIGH7.5Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vecto...
CVE-2024-10220HIGH8.1The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue aff...
CVE-2024-52804HIGH7.5Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in To...
CVE-2024-52802HIGH7.5RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_adv...
CVE-2024-50401HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50400HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50399HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50398HIGH7.2A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50397HIGH8.8A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50396HIGH8.8A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50395HIGH8.8An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If...
CVE-2024-48861HIGH7.8An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil...
CVE-2024-38647HIGH7.5An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerabi...
CVE-2024-38644HIGH8.8An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could...
CVE-2024-37044HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-37041HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-41779HIGH8.1IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security...
CVE-2024-7837HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ...
CVE-2024-11601HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-11104HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-31408HIGH8OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker...
CVE-2024-52052HIGH7.2Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now