2024 CVE Vulnerabilities

39,222 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-46366HIGH8.8A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbi...
CVE-2024-6983HIGH8.8mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backe...
CVE-2024-46472HIGH8.6CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
CVE-2024-46471HIGH7.5The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conten...
CVE-2024-46331HIGH7.2ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. T...
CVE-2024-44912HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
CVE-2024-44911HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).
CVE-2024-44910HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
CVE-2024-40510HIGH8.2Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40509HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-7149HIGH8.8The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In...
CVE-2024-47182HIGH7.5Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwo...
CVE-2024-45773HIGH7.5A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially resu...
CVE-2024-40512HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40511HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-46865HIGH7.1In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be ini...
CVE-2024-46859HIGH7.8In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out ...
CVE-2024-46858HIGH7In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There ar...
CVE-2024-46854HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending pa...
CVE-2024-46853HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: nxp-fspi: fix the KASAN report out-of-bounds b...
CVE-2024-46852HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix off-by-one in CMA heap fault ha...
CVE-2024-46849HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: axg-card: fix 'use-after-free' Buffer...
CVE-2024-46845HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracing/timerlat: Only clear timer if a kthread exi...
CVE-2024-46844HIGH7.8In the Linux kernel, the following vulnerability has been resolved: um: line: always fill *error_out in setup_one_line(...
CVE-2024-46836HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: validate endpoint index fo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now