2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52914HIGH7.5In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr...
CVE-2024-52912HIGH7.5Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse...
CVE-2024-0793HIGH7.7A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking...
CVE-2024-52876HIGH7.5Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una...
CVE-2024-52872HIGH7.5In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.
CVE-2024-52871HIGH7.5In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.
CVE-2024-52867HIGH8.1guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b...
CVE-2024-52415HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object I...
CVE-2024-9887HIGH7.2The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th...
CVE-2024-10645HIGH7.5The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in ...
CVE-2024-10728HIGH8.8The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug...
CVE-2024-9935HIGH7.5The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions ...
CVE-2024-9849HIGH8.8The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up...
CVE-2024-9839HIGH7.3The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2024-9192HIGH8.8The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-11263HIGH8.4When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past t...
CVE-2024-11262HIGH7.8A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affect...
CVE-2024-9500HIGH7.8A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer c...
CVE-2024-38370HIGH7.5GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to downlo...
CVE-2024-49060HIGH8.8Azure Stack HCI Elevation of Privilege Vulnerability
CVE-2024-44759HIGH7.5An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 all...
CVE-2024-51141HIGH7.8An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAut...
CVE-2024-45969HIGH7.5NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e35...
CVE-2024-45608HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it...
CVE-2024-41679HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now