2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-51364HIGH8.8An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a...
CVE-2024-53432HIGH7.5While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ...
CVE-2024-53335HIGH7.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
CVE-2024-53334HIGH8.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
CVE-2024-52287HIGH7.2authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos...
CVE-2024-48288HIGH8TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification...
CVE-2024-48286HIGH8Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
CVE-2024-52799HIGH8.2Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl...
CVE-2024-53429HIGH7.5Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
CVE-2024-28027HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28026HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28025HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-21786HIGH7.2An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies ...
CVE-2024-7026HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informati...
CVE-2024-11088HIGH7.5The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-11589HIGH8.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne...
CVE-2024-11588HIGH7.5A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the ...
CVE-2024-7517HIGH7.8A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms...
CVE-2024-52797HIGH7.5Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and...
CVE-2024-45663HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of serv...
CVE-2024-11409HIGH7.2The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1...
CVE-2024-10898HIGH8.8The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-10788HIGH7.2The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-10403HIGH7.5Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT...
CVE-2024-10400HIGH7.5The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now