2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10947HIGH7.2A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl...
CVE-2024-10946HIGH7.2A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra...
CVE-2024-48325HIGH8.1Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoC...
CVE-2024-50340HIGH7.3symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. ...
CVE-2024-20536HIGH8.8A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (ND...
CVE-2024-20528HIGH7.2A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locat...
CVE-2024-20484HIGH7.5A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could a...
CVE-2024-10827HIGH8.8Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap ...
CVE-2024-10826HIGH8.8Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to po...
CVE-2024-6861HIGH7.5A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena...
CVE-2024-8614HIGH8.8The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-9946HIGH8.1The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe...
CVE-2024-9307HIGH8.8The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ...
CVE-2024-10020HIGH8.1The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an...
CVE-2024-49401HIGH7.1Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi...
CVE-2024-34679HIGH7.1Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone...
CVE-2024-34678HIGH7.8Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup...
CVE-2024-34676HIGH7.3Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker...
CVE-2024-10028HIGH7.5The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S...
CVE-2024-47463HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47462HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47461HIGH7.2An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes...
CVE-2024-51116HIGH8.8Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
CVE-2024-7995HIGH7.8A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a...
CVE-2024-51740HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now