2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-46649HIGH7.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
CVE-2024-46648HIGH7.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
CVE-2024-46645HIGH7.5eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
CVE-2024-47062HIGH8.8Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t...
CVE-2024-47061HIGH8.3Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text ...
CVE-2024-9041HIGH8.8A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Thi...
CVE-2024-9037HIGH7.3A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown...
CVE-2024-9035HIGH7.3A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This af...
CVE-2024-9034HIGH7.3A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ...
CVE-2024-9032HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec...
CVE-2024-41721HIGH8.1An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti...
CVE-2024-47000HIGH7.5Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre...
CVE-2024-45810HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl...
CVE-2024-45809HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro...
CVE-2024-45807HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2...
CVE-2024-9006HIGH8.8A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ...
CVE-2024-45410HIGH7.5Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s...
CVE-2024-43496HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43489HIGH8.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-9001HIGH8.8A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the...
CVE-2024-38016HIGH7.8Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2024-8698HIGH7.7A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly...
CVE-2024-8375HIGH7.8There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres...
CVE-2024-7737HIGH8.7A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ...
CVE-2024-45862HIGH7.5Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now