2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26295HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26294HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-1866Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d...
CVE-2024-1865Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d...
CVE-2024-1864Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d...
CVE-2024-0763HIGH8.1Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path t...
CVE-2024-24027HIGH7.2SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist...
CVE-2024-27099CRITICAL9.8The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f...
CVE-2024-25846CRITICAL9.1In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, ...
CVE-2024-25843CRITICAL9.8In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addon...
CVE-2024-25841MEDIUM5.9In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated cust...
CVE-2024-25840HIGH7.5In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World ...
CVE-2024-24323HIGH7.2SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via ...
CVE-2024-21742MEDIUM5.3Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi...
CVE-2024-1926CRITICAL9.8A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as c...
CVE-2024-1925HIGH8.1A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of t...
CVE-2024-1924MEDIUM5.3A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect...
CVE-2024-27508HIGH7.5Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
CVE-2024-26464Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-26144MEDIUM5.3Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information lea...
CVE-2024-26143MEDIUM6.1Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action...
CVE-2024-26142HIGH7.5Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept h...
CVE-2024-25400CRITICAL9.8Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third partie...
CVE-2024-25399MEDIUM6.1Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.
CVE-2024-25398HIGH7.5In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service con...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now