2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9849HIGH8.8The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up...
CVE-2024-9839HIGH7.3The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2024-9192HIGH8.8The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-11263HIGH8.4When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past t...
CVE-2024-11262HIGH7.8A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affect...
CVE-2024-9500HIGH7.8A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer c...
CVE-2024-38370HIGH7.5GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to downlo...
CVE-2024-49060HIGH8.8Azure Stack HCI Elevation of Privilege Vulnerability
CVE-2024-44759HIGH7.5An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 all...
CVE-2024-51141HIGH7.8An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAut...
CVE-2024-45969HIGH7.5NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e35...
CVE-2024-45608HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it...
CVE-2024-41679HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability...
CVE-2024-24431HIGH7.5A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service...
CVE-2024-24426HIGH7.5Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation ...
CVE-2024-52510HIGH7.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client...
CVE-2024-52508HIGH8.1Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mai...
CVE-2024-46467HIGH7.8By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f...
CVE-2024-46466HIGH7.8By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)...
CVE-2024-46465HIGH7.8By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46463HIGH7.8By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46462HIGH7.8By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil...
CVE-2024-40638HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulner...
CVE-2024-11251HIGH8.8A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some un...
CVE-2024-52525HIGH7.5Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now