2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38642HIGH7.8An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co...
CVE-2024-38641HIGH7.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-32763HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-21898HIGH8.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-8509HIGH7.5A vulnerability was found in Forklift Controller.  There is no verification against the authorization header except to e...
CVE-2024-45294HIGH8.6The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)...
CVE-2024-44408HIGH7.5D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration...
CVE-2024-8428HIGH8.8The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di...
CVE-2024-6445HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology Dat...
CVE-2024-44739HIGH8.8Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-1744HIGH7.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allow...
CVE-2024-7349HIGH7.2The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injectio...
CVE-2024-39585HIGH8.1Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Pass...
CVE-2024-38486HIGH8.8Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralizati...
CVE-2024-8480HIGH8.8The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due ...
CVE-2024-8247HIGH8.8The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2...
CVE-2024-42495HIGH7.5Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow...
CVE-2024-7591HIGH7.2Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa...
CVE-2024-45401HIGH7.1stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in ver...
CVE-2024-45175HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It...
CVE-2024-45171HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45098HIGH8.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45097HIGH7.1IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod...
CVE-2024-45178HIGH7.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos...
CVE-2024-45173HIGH8.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now