2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47000HIGH7.5Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre...
CVE-2024-45810HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl...
CVE-2024-45809HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro...
CVE-2024-45807HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2...
CVE-2024-9006HIGH8.8A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ...
CVE-2024-45410HIGH7.5Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s...
CVE-2024-43496HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43489HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-9001HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the...
CVE-2024-38016HIGH7.8Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2024-8698HIGH7.7A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly...
CVE-2024-8375HIGH7.8There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres...
CVE-2024-7737HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ...
CVE-2024-45862HIGH7.5Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac...
CVE-2024-45861HIGH7.5Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker...
CVE-2024-45752HIGH7.3logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u...
CVE-2024-46394HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
CVE-2024-46382HIGH7.5A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ...
CVE-2024-7254HIGH7.5Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO...
CVE-2024-37406HIGH7.5In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w...
CVE-2024-46373HIGH8.8Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
CVE-2024-44589HIGH8.8Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta...
CVE-2024-39339HIGH7.5A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c...
CVE-2024-8287HIGH7.5Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the...
CVE-2024-34057HIGH7.5Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now