2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8592HIGH7.8A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corrupti...
CVE-2024-8591HIGH7.8A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer O...
CVE-2024-8590HIGH7.8A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerabil...
CVE-2024-8589HIGH7.8A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v...
CVE-2024-8588HIGH7.8A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v...
CVE-2024-7992HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Sta...
CVE-2024-7991HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Ou...
CVE-2024-44080HIGH7.5In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resul...
CVE-2024-10488HIGH8.8Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap c...
CVE-2024-10487HIGH8.8Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds m...
CVE-2024-8587HIGH7.8A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Ov...
CVE-2024-50456HIGH8.8Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-50455HIGH8.8Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-48955HIGH8.1Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi...
CVE-2024-9990HIGH8.8The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This...
CVE-2024-8924HIGH7.5ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability...
CVE-2024-50466HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm...
CVE-2024-7985HIGH8.8The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ...
CVE-2024-49769HIGH7.5Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ...
CVE-2024-7962HIGH7.5An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio...
CVE-2024-7807HIGH7.5A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi...
CVE-2024-7783HIGH7.5mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,...
CVE-2024-7474HIGH8.1In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o...
CVE-2024-6674HIGH7.1A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc...
CVE-2024-41153HIGH7.2Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now