2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45710HIGH7.8SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This...
CVE-2024-45693HIGH8.8Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ...
CVE-2024-45462HIGH7.1The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex...
CVE-2024-45219HIGH8.5Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v...
CVE-2024-45217HIGH8.1Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore...
CVE-2024-8746HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi...
CVE-2024-8507HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2024-49340HIGH8.8IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic...
CVE-2024-38190HIGH8.6Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo...
CVE-2024-38139HIGH8.8Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2024-45085HIGH7.5IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un...
CVE-2024-9965HIGH8.8Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh...
CVE-2024-9961HIGH8.8Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ...
CVE-2024-9960HIGH7.5Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-9959HIGH8.8Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the ren...
CVE-2024-9957HIGH8.8Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to en...
CVE-2024-9956HIGH7.8Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local att...
CVE-2024-9955HIGH8.8Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exp...
CVE-2024-9954HIGH8.8Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-9594HIGH8.1A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable...
CVE-2024-48783HIGH7.5An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postg...
CVE-2024-44775HIGH7.5kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the b...
CVE-2024-41311HIGH8.1In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with fo...
CVE-2024-21285HIGH7.1Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R...
CVE-2024-21284HIGH7.1Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now