2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13040HIGH8.8The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling ...
CVE-2024-12839HIGH8.8The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypas...
CVE-2024-12838HIGH8.8The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerabili...
CVE-2024-13058MEDIUM4.8An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote...
CVE-2024-13051HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-13050HIGH7.8Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili...
CVE-2024-13049HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2024-13048HIGH7.8Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13047HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2024-13046HIGH7.8Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13045HIGH7.8Ashlar-Vellum Cobalt AR File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability...
CVE-2024-13044HIGH7.8Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-13043HIGH7.8Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t...
CVE-2024-13042MEDIUM5.3A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been clas...
CVE-2024-12753HIGH7.3Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to e...
CVE-2024-12752HIGH7.8Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attack...
CVE-2024-12751HIGH7.8Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2024-11946MEDIUM6.5iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This...
CVE-2024-11944HIGH8.8iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability al...
CVE-2024-56801CRITICAL9.8Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version ...
CVE-2024-56800HIGH7.4Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions pr...
CVE-2024-56799CRITICAL10Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistak...
CVE-2024-46542MEDIUM6.5Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.
CVE-2024-56734MEDIUM6.1Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif...
CVE-2024-56733MEDIUM5.7Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has bee...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now