2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24431HIGH7.5A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service...
CVE-2024-24426HIGH7.5Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation ...
CVE-2024-52510HIGH7.5The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client...
CVE-2024-52508HIGH8.1Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mai...
CVE-2024-46467HIGH7.8By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f...
CVE-2024-46466HIGH7.8By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)...
CVE-2024-46465HIGH7.8By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46463HIGH7.8By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file...
CVE-2024-46462HIGH7.8By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil...
CVE-2024-40638HIGH8.8GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulner...
CVE-2024-11251HIGH8.8A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some un...
CVE-2024-52525HIGH7.5Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen...
CVE-2024-52519HIGH8.2Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so ...
CVE-2024-50654HIGH7.5lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quant...
CVE-2024-50653HIGH7.5CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able t...
CVE-2024-44625HIGH8.8Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
CVE-2024-39726HIGH8.2IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In...
CVE-2024-11248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function f...
CVE-2024-52555HIGH7.8In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer...
CVE-2024-50650HIGH7.5python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of us...
CVE-2024-50647HIGH7.5The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user infor...
CVE-2024-41784HIGH7.5IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse dire...
CVE-2024-11245HIGH7.5A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0. This issue affects some...
CVE-2024-50986HIGH7.3An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.
CVE-2024-11242HIGH7.2A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now