2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8644HIGH7.5Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipul...
CVE-2024-8609HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Infor...
CVE-2024-9136HIGH7.5Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulner...
CVE-2024-47294HIGH7.5Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of thi...
CVE-2024-47293HIGH7.5Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affec...
CVE-2024-38861HIGH7.4Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traff...
CVE-2024-39435HIGH7.8In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of ...
CVE-2024-9029HIGH7.5A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read...
CVE-2024-7400HIGH8.5The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file...
CVE-2024-9130HIGH7.2The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via...
CVE-2024-8922HIGH8.8The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject...
CVE-2024-7714HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ...
CVE-2024-7713HIGH7.5The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al...
CVE-2024-47076HIGH8.6CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for...
CVE-2024-40508HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40507HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40506HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-6769HIGH8.4A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win...
CVE-2024-7594HIGH8.8Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip...
CVE-2024-47180HIGH8.8Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-...
CVE-2024-47179HIGH8.8RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po...
CVE-2024-47169HIGH8.8Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p...
CVE-2024-47126HIGH8.8The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func...
CVE-2024-39577HIGH8.8Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ...
CVE-2024-45982HIGH8.8A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now