2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22458MEDIUM5.3Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network ...
CVE-2024-22457HIGH8.8Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A ...
CVE-2024-25972HIGH8.3Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co...
CVE-2024-1120MEDIUM5.3The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce pl...
CVE-2024-25091CRITICAL9.1Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or ...
CVE-2024-0692HIGH8.8The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-27950HIGH8.8Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <=...
CVE-2024-27949MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n...
CVE-2024-25554Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-25553Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-25552HIGH7.8A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.
CVE-2024-1859HIGH8.8The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injec...
CVE-2024-25386HIGH8.8Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attac...
CVE-2024-25293CRITICAL9.3mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
CVE-2024-22891CRITICAL9.8Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
CVE-2024-25578HIGH7.8 MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied d...
CVE-2024-22100HIGH7.8 MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnera...
CVE-2024-1941HIGH7.8 Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow...
CVE-2024-2045MEDIUM5.5Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the ...
CVE-2024-2022CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affect...
CVE-2024-2021CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affe...
CVE-2024-0403MEDIUM6.5Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the appli...
CVE-2024-27294HIGH7.8dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compil...
CVE-2024-2009HIGH7.5A vulnerability was found in Nway Pro 9. It has been rated as problematic. Affected by this issue is the function ajax_l...
CVE-2024-27662MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability al...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now