2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43812HIGH8.6Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthent...
CVE-2024-42643HIGH7.5Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligne...
CVE-2024-31029HIGH8.2An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote ...
CVE-2024-10231HIGH8.8Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-10230HIGH8.8Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-10229HIGH8.1Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass s...
CVE-2024-48903HIGH7.8An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate ...
CVE-2024-45334HIGH7.8Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that c...
CVE-2024-41183HIGH7.8Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that ...
CVE-2024-39753HIGH7.5An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code o...
CVE-2024-9287HIGH7.8A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en...
CVE-2024-48570HIGH7.5Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param...
CVE-2024-45518HIGH8.8An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,...
CVE-2024-48605HIGH7.8An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v...
CVE-2024-47819HIGH8.7Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver...
CVE-2024-38002HIGH8.8The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1...
CVE-2024-26273HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an...
CVE-2024-26272HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an...
CVE-2024-26271HIGH8.8Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a...
CVE-2024-10234HIGH7.3A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th...
CVE-2024-9050HIGH7.8A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper...
CVE-2024-9987HIGH8.8A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func...
CVE-2024-35308HIGH8.8A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi...
CVE-2024-9627HIGH7.3The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing...
CVE-2024-10002HIGH8.8The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now