2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-46937HIGH7.5An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Sec...
CVE-2024-46424HIGH7.5TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which ...
CVE-2024-45696HIGH8.8Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, ...
CVE-2024-39613HIGH7.8Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows ...
CVE-2024-8779HIGH8.8OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowi...
CVE-2024-8777HIGH7.5OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar...
CVE-2024-46943HIGH7.5An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue contr...
CVE-2024-8876HIGH7.5A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by th...
CVE-2024-46938HIGH7.5An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 ...
CVE-2024-8869HIGH8.1A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The ...
CVE-2024-8864HIGH8.8A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerabi...
CVE-2024-6482HIGH8.8The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2024-8669HIGH7.2The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' ...
CVE-2024-8479HIGH7.3The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This ...
CVE-2024-8246HIGH8.8The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-8271HIGH7.3The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-44095HIGH7.8In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This co...
CVE-2024-44094HIGH7.8In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This...
CVE-2024-44093HIGH7.8In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This...
CVE-2024-44092HIGH7.8There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could l...
CVE-2024-29779HIGH7.8there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privile...
CVE-2024-8784HIGH8.8A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnera...
CVE-2024-8281HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8280HIGH7.2An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil...
CVE-2024-8279HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now