2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45981HIGH8.8A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u...
CVE-2024-45980HIGH8.8A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte...
CVE-2024-45979HIGH8.8A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us...
CVE-2024-44860HIGH7.5An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s...
CVE-2024-37125HIGH7.5Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum...
CVE-2024-43191HIGH8.8IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia...
CVE-2024-41605HIGH8.4In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat...
CVE-2024-30134HIGH7.5The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un...
CVE-2024-46330HIGH7.4VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ...
CVE-2024-46329HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.
CVE-2024-46328HIGH8VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,...
CVE-2024-7107HIGH7.5Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all...
CVE-2024-8704HIGH7.2The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a...
CVE-2024-8126HIGH8.8The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'...
CVE-2024-9199HIGH7.5Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ...
CVE-2024-47197HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M...
CVE-2024-0132HIGH8.3NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de...
CVE-2024-47045HIGH7.8Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, ...
CVE-2024-47330HIGH8.8Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i...
CVE-2024-8404HIGH7.8An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print...
CVE-2024-47083HIGH7.5Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior...
CVE-2024-47315HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= ...
CVE-2024-47305HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge...
CVE-2024-47082HIGH8Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de...
CVE-2024-46489HIGH8.8A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now