2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-44013HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Cal...
CVE-2024-44012HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Su...
CVE-2024-44011HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP T...
CVE-2024-9532HIGH8.8A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects th...
CVE-2024-47841HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation...
CVE-2024-47846HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request ...
CVE-2024-47845HIGH8.2Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code ...
CVE-2024-47911HIGH7.2In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-membe...
CVE-2024-47910HIGH7.2An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Admini...
CVE-2024-37869HIGH8.8File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi...
CVE-2024-37868HIGH8.8File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi...
CVE-2024-9054HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Inform...
CVE-2024-43684HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-...
CVE-2024-46078HIGH7.5itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the ...
CVE-2024-41512HIGH8.8A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attacker...
CVE-2024-38040HIGH7.5There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthen...
CVE-2024-46486HIGH8TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv fu...
CVE-2024-47769HIGH7.5IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. U...
CVE-2024-47768HIGH8.1Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to ...
CVE-2024-47183HIGH8.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser...
CVE-2024-9515HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function...
CVE-2024-9514HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects ...
CVE-2024-47790HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-...
CVE-2024-47789HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentic...
CVE-2024-47655HIGH8.8This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now