2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47080HIGH8.7matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t...
CVE-2024-48282HIGH7.6A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag...
CVE-2024-48280HIGH7.6A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen...
CVE-2024-48279HIGH7.6A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme...
CVE-2024-9975HIGH8.8A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t...
CVE-2024-49387HIGH7.5Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ...
CVE-2024-45276HIGH7.5An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2024-45273HIGH7.8An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ...
CVE-2024-45272HIGH7.5An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with...
CVE-2024-45271HIGH7.8An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
CVE-2024-9983HIGH7.5Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo...
CVE-2024-9981HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9980HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9837HIGH7.3The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution ...
CVE-2024-46898HIGH7.5SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If t...
CVE-2024-0129HIGH7.8NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe...
CVE-2024-9971HIGH8.8The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing...
CVE-2024-9970HIGH8.8The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular priv...
CVE-2024-9968HIGH8.8WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in...
CVE-2024-9820HIGH7.5The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i...
CVE-2024-9687HIGH8.8The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3...
CVE-2024-6207HIGH7.5CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send ...
CVE-2024-48911HIGH7.8OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0...
CVE-2024-48824HIGH7.5An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack...
CVE-2024-48822HIGH8.8Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now