2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-58366HIGH8.8SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script...
CVE-2024-58365HIGH7.1SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls ...
CVE-2024-58364HIGH7.1SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer...
CVE-2024-58362HIGH8.8SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operati...
CVE-2024-58361HIGH7.1SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code ...
CVE-2024-58359HIGH7.1SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY r...
CVE-2024-58357HIGH7.1SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics whe...
CVE-2024-34268HIGH7.1EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow ...
CVE-2024-32386HIGH7.3Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at...
CVE-2024-7708HIGH7.5For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti...
CVE-2024-6228HIGH7.5The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value befo...
CVE-2024-58352HIGH7.5Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr...
CVE-2024-23581HIGH7.8The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized ...
CVE-2024-49269HIGH7.1Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
CVE-2024-32949HIGH8.3Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con...
CVE-2024-32729HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio...
CVE-2024-39575HIGH7.4update_disk_psu_baseline.sh requires password in plain text
CVE-2024-38487HIGH7api-gateway container running with root privilege would allow an attacker to escape the container and access host system...
CVE-2024-24909HIGH8.8Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga...
CVE-2024-22447HIGH7.8Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker...
CVE-2024-14036HIGH8.7Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-...
CVE-2024-52011HIGH8.3launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in...
CVE-2024-40646HIGH8.6Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co...
CVE-2024-56462HIGH8.8IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive t...
CVE-2024-36334HIGH7Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the insta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now