2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42011HIGH7.5The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.
CVE-2024-50457HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-50453HIGH8.8Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusi...
CVE-2024-50436HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-50435HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-50434HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-48826HIGH8.8Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arb...
CVE-2024-48825HIGH8.8Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute a...
CVE-2024-48196HIGH7.5An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post pa...
CVE-2024-48178HIGH8.1newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
CVE-2024-6245HIGH7.4Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker ...
CVE-2024-42028HIGH8.8A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (V...
CVE-2024-49761HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has ma...
CVE-2024-45802HIGH7.5Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premat...
CVE-2024-10455HIGH7.5Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block
CVE-2024-50574HIGH7.5In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk func...
CVE-2024-50488HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authenti...
CVE-2024-10447HIGH8.8A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vul...
CVE-2024-50442HIGH7.2Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-a...
CVE-2024-50416HIGH8.8Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer ...
CVE-2024-50408HIGH8.8Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affec...
CVE-2024-48074HIGH8An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a mali...
CVE-2024-10446HIGH7.2A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an ...
CVE-2024-9162HIGH7.2The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing...
CVE-2024-10439HIGH7.5The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now