2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9307HIGH8.8The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ...
CVE-2024-10020HIGH8.1The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an...
CVE-2024-49401HIGH7.1Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi...
CVE-2024-34679HIGH7.1Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone...
CVE-2024-34678HIGH7.8Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup...
CVE-2024-34676HIGH7.3Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker...
CVE-2024-10028HIGH7.5The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S...
CVE-2024-47463HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47462HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47461HIGH7.2An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes...
CVE-2024-51116HIGH8.8Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
CVE-2024-7995HIGH7.8A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a...
CVE-2024-51740HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests o...
CVE-2024-51735HIGH8.7Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when ...
CVE-2024-51382HIGH8.4Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password...
CVE-2024-51381HIGH8.4Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for ad...
CVE-2024-51380HIGH8.4Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows...
CVE-2024-51379HIGH8.4Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description ...
CVE-2024-51240HIGH8An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root v...
CVE-2024-50333HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is ...
CVE-2024-50332HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient i...
CVE-2024-49774HIGH7.2SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relie...
CVE-2024-49772HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM ve...
CVE-2024-50131HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validatin...
CVE-2024-50130HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: must hold reference on net namespac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now