2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8559HIGH7.2A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue aff...
CVE-2024-42024HIGH8.8A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remo...
CVE-2024-42023HIGH8.8An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remot...
CVE-2024-42019HIGH8A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This atta...
CVE-2024-40718HIGH8.8A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through e...
CVE-2024-40714HIGH8.3An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to...
CVE-2024-40713HIGH7.8A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alte...
CVE-2024-40712HIGH7.8A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perfor...
CVE-2024-40710HIGH8.8A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service ...
CVE-2024-40709HIGH7.8A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to ...
CVE-2024-39718HIGH8.1An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with...
CVE-2024-39715HIGH8.5A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitra...
CVE-2024-38651HIGH8.5A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to...
CVE-2024-36138HIGH8.1Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions ...
CVE-2024-8557HIGH7.5A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affect...
CVE-2024-40681HIGH8.8IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define...
CVE-2024-37068HIGH7.5IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t...
CVE-2024-8523HIGH7.2A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatD...
CVE-2024-45498HIGH8.8Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an ...
CVE-2024-45034HIGH8.8Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG fold...
CVE-2024-44845HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value para...
CVE-2024-44844HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name param...
CVE-2024-34158HIGH7.5Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
CVE-2024-34156HIGH7.5Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. T...
CVE-2024-7652HIGH7.5An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now