2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7023HIGH8.8Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv...
CVE-2024-7018HIGH7.8Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit hea...
CVE-2024-42861HIGH7.5An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted...
CVE-2024-46639HIGH7.6A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML...
CVE-2024-37779HIGH8.8WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t...
CVE-2024-39842HIGH7.2A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-0005HIGH8.8A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel...
CVE-2024-0004HIGH7.2A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to...
CVE-2024-0003HIGH7.2A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an ...
CVE-2024-40442HIGH7.2An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-47066HIGH8.8Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger...
CVE-2024-46985HIGH7.5DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in...
CVE-2024-41228HIGH7.6A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es...
CVE-2024-23934HIGH8.8Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-7835HIGH8.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Infor...
CVE-2024-45348HIGH8.8Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack ...
CVE-2024-8606HIGH8.8Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass...
CVE-2024-9093HIGH7.2A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0....
CVE-2024-43989HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects J...
CVE-2024-9081HIGH7.5A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...
CVE-2024-9076HIGH8.8A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce...
CVE-2024-47221HIGH7.5CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
CVE-2024-47210HIGH8.8Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be...
CVE-2024-42323HIGH8.8SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be ...
CVE-2024-6785HIGH7.1The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now