2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34729HIGH7.8In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to...
CVE-2024-34719HIGH7.8In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca...
CVE-2024-31337HIGH7.8In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This...
CVE-2024-23715HIGH7.8In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea...
CVE-2024-9413HIGH8The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p...
CVE-2024-52291HIGH7.2Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v...
CVE-2024-51996HIGH7.5Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p...
CVE-2024-52299HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService...
CVE-2024-52298HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an...
CVE-2024-52293HIGH7.2Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi...
CVE-2024-50972HIGH7.2A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker...
CVE-2024-50971HIGH7.2A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to...
CVE-2024-50970HIGH8.8A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta...
CVE-2024-10013HIGH7.8In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through...
CVE-2024-10012HIGH7.8In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i...
CVE-2024-50854HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
CVE-2024-50853HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
CVE-2024-50852HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ...
CVE-2024-49506HIGH7.3Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se...
CVE-2024-49504HIGH7grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
CVE-2024-48989HIGH7.5A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke...
CVE-2024-47574HIGH7.8A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ...
CVE-2024-4741HIGH7.5Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre...
CVE-2024-9409HIGH7.5CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re...
CVE-2024-8937HIGH8.3CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now