2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-50596HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50595HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50594HIGH7.5An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT...
CVE-2024-50385HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-50384HIGH7.5A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-36465HIGH8.8A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer...
CVE-2024-13567HIGH7.5The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2024-54533HIGH7A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS...
CVE-2024-12021HIGH8.5Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf...
CVE-2024-7577HIGH7.5IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ...
CVE-2024-57083HIGH7.5A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac...
CVE-2024-54362HIGH8.1Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This is...
CVE-2024-54291HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass plugin...
CVE-2024-51624HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-...
CVE-2024-48615HIGH7.5Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa...
CVE-2024-7407HIGH8.2Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ...
CVE-2024-11504HIGH8.6Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w...
CVE-2024-13939HIGH7.5String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the...
CVE-2024-49565HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49564HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49563HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55073HIGH7.6A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-12905HIGH7.5An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ...
CVE-2024-9773HIGH8An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from...
CVE-2024-45356HIGH7.3A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now