2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48570HIGH7.5Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param...
CVE-2024-45518HIGH8.8An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,...
CVE-2024-48605HIGH7.8An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v...
CVE-2024-47819HIGH8.7Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver...
CVE-2024-38002HIGH8.8The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1...
CVE-2024-26273HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an...
CVE-2024-26272HIGH8.8Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an...
CVE-2024-26271HIGH8.8Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a...
CVE-2024-10234HIGH7.3A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th...
CVE-2024-9050HIGH7.8A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper...
CVE-2024-9987HIGH8.8A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func...
CVE-2024-35308HIGH8.8A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi...
CVE-2024-9627HIGH7.3The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing...
CVE-2024-10002HIGH8.8The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ...
CVE-2024-9677HIGH7.8The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version ...
CVE-2024-8901HIGH7.5The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio...
CVE-2024-10125HIGH7.5The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#vali...
CVE-2024-41714HIGH8.8A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution...
CVE-2024-30158HIGH7.2A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attac...
CVE-2024-30157HIGH7.2A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenti...
CVE-2024-50063HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to di...
CVE-2024-50061HIGH7In the Linux kernel, the following vulnerability has been resolved: i3c: master: cdns: Fix use after free vulnerability...
CVE-2024-50059HIGH7In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix use after free vulnerabi...
CVE-2024-50055HIGH7.8In the Linux kernel, the following vulnerability has been resolved: driver core: bus: Fix double free in driver API bus...
CVE-2024-50047HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now