2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47637HIGH8.8Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th...
CVE-2024-47351HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxS...
CVE-2024-22032HIGH7.1A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi...
CVE-2024-22030HIGH8A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m...
CVE-2024-22029HIGH7.8Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalat...
CVE-2024-49271HIGH7.2Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Ad...
CVE-2024-10024HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This ...
CVE-2024-10023HIGH8.8A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability aff...
CVE-2024-8040HIGH7.7An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R...
CVE-2024-9858HIGH7.8There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo...
CVE-2024-45711HIGH8.8SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible dependi...
CVE-2024-45710HIGH7.8SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This...
CVE-2024-45693HIGH8.8Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ...
CVE-2024-45462HIGH7.1The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex...
CVE-2024-45219HIGH8.5Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v...
CVE-2024-45217HIGH8.1Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore...
CVE-2024-8746HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi...
CVE-2024-8507HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2024-49340HIGH8.8IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic...
CVE-2024-38190HIGH8.6Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo...
CVE-2024-38139HIGH8.8Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2024-45085HIGH7.5IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un...
CVE-2024-9965HIGH8.8Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh...
CVE-2024-9961HIGH8.8Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ...
CVE-2024-9960HIGH7.5Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now