2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37285HIGH7.2A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document con...
CVE-2024-52302HIGH8.7common-user-management is a robust Spring Boot application featuring user management services designed to control user a...
CVE-2024-11214HIGH7.2A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vu...
CVE-2024-11213HIGH7.2A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This...
CVE-2024-11136HIGH8.2The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application ...
CVE-2024-10921HIGH8.1An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing speciall...
CVE-2024-11212HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0....
CVE-2024-11211HIGH7.2A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the com...
CVE-2024-9633HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions start...
CVE-2024-11208HIGH8.1A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi...
CVE-2024-10962HIGH8.8The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...
CVE-2024-10979HIGH8.8Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitiv...
CVE-2024-7730HIGH7.8A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input call...
CVE-2024-45670HIGH8.1IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowi...
CVE-2024-9693HIGH8.8An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 pr...
CVE-2024-9472HIGH8.7A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and P...
CVE-2024-50305HIGH7.5Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S...
CVE-2024-47916HIGH7.5Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-47915HIGH7.5VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-45254HIGH7.5VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-45253HIGH7.5Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-38479HIGH7.5Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ...
CVE-2024-2551HIGH7.5A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to st...
CVE-2024-2550HIGH7.5A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an u...
CVE-2024-11206HIGH7.5Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user info...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now