2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45148HIGH8.8Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v...
CVE-2024-45117HIGH7.6Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation...
CVE-2024-45116HIGH8.1Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS)...
CVE-2024-6747HIGH7.5Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to...
CVE-2024-9781HIGH7.5AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet i...
CVE-2024-9156HIGH7.5The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping o...
CVE-2024-9022HIGH7.2The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘o...
CVE-2024-9581HIGH7.3The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i...
CVE-2024-9522HIGH8.8The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2....
CVE-2024-9519HIGH7.2The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check...
CVE-2024-48958HIGH7.8execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c...
CVE-2024-48957HIGH7.8execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c...
CVE-2024-39525HIGH8.7An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju...
CVE-2024-39516HIGH8.7An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS E...
CVE-2024-39515HIGH8.7An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Network...
CVE-2024-3656HIGH8.1A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access adminis...
CVE-2024-9473HIGH7.8A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticat...
CVE-2024-9468HIGH7.5A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-...
CVE-2024-9463HIGH7.5An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitra...
CVE-2024-46307HIGH7.5A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.
CVE-2024-43610HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s...
CVE-2024-46316HIGH8DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cg...
CVE-2024-46304HIGH7.5A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the...
CVE-2024-46292HIGH7.5A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserte...
CVE-2024-8048HIGH7.8In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now