2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10611HIGH8.8A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of t...
CVE-2024-10610HIGH8.8A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function del...
CVE-2024-10599HIGH7.5A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects so...
CVE-2024-10596HIGH8.8A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEn...
CVE-2024-10594HIGH8.8A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of ...
CVE-2024-48360HIGH7.5Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.p...
CVE-2024-39722HIGH7.5An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via ...
CVE-2024-39721HIGH7.5An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until compl...
CVE-2024-39720HIGH8.2An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file c...
CVE-2024-39719HIGH7.5An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the C...
CVE-2024-51066HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Manage...
CVE-2024-48200HIGH8.4An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove fun...
CVE-2024-8185HIGH7.5Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a den...
CVE-2024-51254HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-49685HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds...
CVE-2024-43984HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue af...
CVE-2024-43383HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's...
CVE-2024-21537HIGH8.9Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse...
CVE-2024-48311HIGH8.8Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
CVE-2024-10559HIGH7.8A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected b...
CVE-2024-51426HIGH8.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51425HIGH8.8An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ...
CVE-2024-51243HIGH7.2The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy...
CVE-2024-48735HIGH7.7Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ...
CVE-2024-48734HIGH8.8Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now