2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9981HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9980HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9837HIGH7.3The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution ...
CVE-2024-46898HIGH7.5SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If t...
CVE-2024-0129HIGH7.8NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe...
CVE-2024-9971HIGH8.8The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing...
CVE-2024-9970HIGH8.8The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular priv...
CVE-2024-9968HIGH8.8WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in...
CVE-2024-9820HIGH7.5The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i...
CVE-2024-9687HIGH8.8The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3...
CVE-2024-6207HIGH7.5CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send ...
CVE-2024-48911HIGH7.8OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0...
CVE-2024-48824HIGH7.5An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack...
CVE-2024-48822HIGH8.8Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...
CVE-2024-48792HIGH7.5An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update p...
CVE-2024-48791HIGH7.5An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive informati...
CVE-2024-48789HIGH7.5An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via th...
CVE-2024-47831HIGH7.5Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2....
CVE-2024-48799HIGH7.5An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information...
CVE-2024-48798HIGH7.5An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive inform...
CVE-2024-48797HIGH7.5An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive in...
CVE-2024-48796HIGH7.5An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update ...
CVE-2024-45733HIGH8.8In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or...
CVE-2024-45731HIGH8In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "a...
CVE-2024-9823HIGH7.5There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now