2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9120HIGH8.8Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially explo...
CVE-2024-8942HIGH8.2Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input vali...
CVE-2024-8914HIGH7.2The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulner...
CVE-2024-8497HIGH8.7Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could...
CVE-2024-46936HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation i...
CVE-2024-46935HIGH7.5Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers...
CVE-2024-46610HIGH7.5An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including...
CVE-2024-46609HIGH7.5An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat...
CVE-2024-46607HIGH7.6Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a...
CVE-2024-45373HIGH8.8Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
CVE-2024-39928HIGH7.5In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the To...
CVE-2024-21545HIGH8.2Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf...
CVE-2024-8623HIGH7.3The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in al...
CVE-2024-8795HIGH8.8The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-7023HIGH8.8Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv...
CVE-2024-7018HIGH7.8Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit hea...
CVE-2024-42861HIGH7.5An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted...
CVE-2024-46639HIGH7.6A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML...
CVE-2024-37779HIGH8.8WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t...
CVE-2024-39842HIGH7.2A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-0005HIGH8.8A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel...
CVE-2024-0004HIGH7.2A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to...
CVE-2024-0003HIGH7.2A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an ...
CVE-2024-40442HIGH7.2An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-47066HIGH8.8Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now