2024 CVE Vulnerabilities

39,222 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7714HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ...
CVE-2024-7713HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al...
CVE-2024-47076HIGH8.6CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for...
CVE-2024-40508HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40507HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40506HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-6769HIGH8.4A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win...
CVE-2024-7594HIGH8.8Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip...
CVE-2024-47180HIGH8.8Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-...
CVE-2024-47179HIGH8.8RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po...
CVE-2024-47169HIGH8.8Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47126HIGH8.8The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func...
CVE-2024-39577HIGH8.8Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ...
CVE-2024-45982HIGH8.8A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ...
CVE-2024-45981HIGH8.8A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u...
CVE-2024-45980HIGH8.8A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte...
CVE-2024-45979HIGH8.8A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us...
CVE-2024-44860HIGH7.5An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s...
CVE-2024-37125HIGH7.5Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum...
CVE-2024-43191HIGH8.8IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia...
CVE-2024-41605HIGH8.4In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat...
CVE-2024-30134HIGH7.5The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un...
CVE-2024-46330HIGH7.4VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ...
CVE-2024-46329HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2024-46328HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now