2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8557HIGH7.5A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affect...
CVE-2024-40681HIGH8.8IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define...
CVE-2024-37068HIGH7.5IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t...
CVE-2024-8523HIGH7.2A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatD...
CVE-2024-45498HIGH8.8Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an ...
CVE-2024-45034HIGH8.8Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG fold...
CVE-2024-44845HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value para...
CVE-2024-44844HIGH8.8DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name param...
CVE-2024-34158HIGH7.5Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
CVE-2024-34156HIGH7.5Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. T...
CVE-2024-7652HIGH7.5An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially...
CVE-2024-38642HIGH7.8An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co...
CVE-2024-38641HIGH7.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-32763HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-21898HIGH8.8An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-8509HIGH7.5A vulnerability was found in Forklift Controller.  There is no verification against the authorization header except to e...
CVE-2024-45294HIGH8.6The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)...
CVE-2024-44408HIGH7.5D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration...
CVE-2024-8428HIGH8.8The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di...
CVE-2024-6445HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology Dat...
CVE-2024-44739HIGH8.8Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-1744HIGH7.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allow...
CVE-2024-7349HIGH7.2The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injectio...
CVE-2024-39585HIGH8.1Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Pass...
CVE-2024-38486HIGH8.8Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralizati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now