2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45199HIGH8.8insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param...
CVE-2024-45198HIGH8.8insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i...
CVE-2024-4877HIGH8.8OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi...
CVE-2024-53868HIGH7.5Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffi...
CVE-2024-37917HIGH7.5Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so...
CVE-2024-36337HIGH7.9Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-36336HIGH7.9Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a...
CVE-2024-36328HIGH7.3Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ...
CVE-2024-56474HIGH8.8IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2024-25051HIGH7.2IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p...
CVE-2024-50597HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50596HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50595HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50594HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50385HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-50384HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-36465HIGH8.8A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer...
CVE-2024-13567HIGH7.5The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2024-54533HIGH7A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS...
CVE-2024-12021HIGH8.5Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf...
CVE-2024-7577HIGH7.5IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ...
CVE-2024-57083HIGH7.5A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac...
CVE-2024-54362HIGH8.1Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This is...
CVE-2024-54291HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass plugin...
CVE-2024-51624HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now