2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47404HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-47137HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-10097HIGH8.1The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to...
CVE-2024-9459HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in re...
CVE-2024-10810HIGH7.5A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ...
CVE-2024-10809HIGH7.5A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some ...
CVE-2024-10808HIGH7.5A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability ...
CVE-2024-31998HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This i...
CVE-2024-51734HIGH8.7Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delet...
CVE-2024-51500HIGH7.5Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets ...
CVE-2024-10805HIGH8.8A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. T...
CVE-2024-30619HIGH7.5Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the numb...
CVE-2024-30616HIGH8.8Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens...
CVE-2024-51329HIGH8.8A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in...
CVE-2024-51326HIGH7.5SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrar...
CVE-2024-51127HIGH7.1An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensit...
CVE-2024-48336HIGH8.4The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b...
CVE-2024-48809HIGH7.5An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a ...
CVE-2024-51626HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom...
CVE-2024-45893HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45891HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45890HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when ...
CVE-2024-45889HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45888HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...
CVE-2024-45887HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now