2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43969HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spi...
CVE-2024-46982HIGH7.5Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible...
CVE-2024-8957HIGH7.2PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not su...
CVE-2024-8905HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially expl...
CVE-2024-8904HIGH8.8Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-45398HIGH8.8Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious ...
CVE-2024-8949HIGH8.8A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown...
CVE-2024-8948HIGH7.5A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function m...
CVE-2024-8947HIGH8.1A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an ...
CVE-2024-8946HIGH7.5A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umo...
CVE-2024-8900HIGH7.5An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigation...
CVE-2024-43460HIGH8.8Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke...
CVE-2024-8945HIGH8.8A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulner...
CVE-2024-42503HIGH7.2Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio...
CVE-2024-42502HIGH7.2Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t...
CVE-2024-42501HIGH7.2An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability all...
CVE-2024-8768HIGH7.5A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, res...
CVE-2024-7788HIGH7.8Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows ...
CVE-2024-47049HIGH8.2The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URL...
CVE-2024-47047HIGH7.5An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of ...
CVE-2024-22303HIGH8.8Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:...
CVE-2024-21743HIGH8.8Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L...
CVE-2024-46362HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-46085HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-5998HIGH7.8A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now