2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-46985HIGH7.5DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in...
CVE-2024-41228HIGH7.6A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es...
CVE-2024-23934HIGH8.8Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-7835HIGH8.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Infor...
CVE-2024-45348HIGH8.8Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack ...
CVE-2024-8606HIGH8.8Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass...
CVE-2024-9093HIGH7.2A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0....
CVE-2024-43989HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects J...
CVE-2024-9081HIGH7.5A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...
CVE-2024-9076HIGH8.8A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce...
CVE-2024-47221HIGH7.5CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
CVE-2024-47210HIGH8.8Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be...
CVE-2024-42323HIGH8.8SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be ...
CVE-2024-6785HIGH7.1The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf...
CVE-2024-46649HIGH7.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
CVE-2024-46648HIGH7.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
CVE-2024-46645HIGH7.5eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
CVE-2024-47062HIGH8.8Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t...
CVE-2024-47061HIGH8.3Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text ...
CVE-2024-9041HIGH8.8A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Thi...
CVE-2024-9037HIGH7.3A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown...
CVE-2024-9035HIGH7.3A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This af...
CVE-2024-9034HIGH7.3A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ...
CVE-2024-9032HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec...
CVE-2024-41721HIGH8.1An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now