2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45174HIGH8.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-...
CVE-2024-45170HIGH8.1An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low p...
CVE-2024-20440HIGH7.5A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf...
CVE-2024-8391HIGH7.5In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GA...
CVE-2024-45075HIGH8.8IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to es...
CVE-2024-45053HIGH7.2Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email ...
CVE-2024-45050HIGH7.1Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messag...
CVE-2024-44859HIGH8Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
CVE-2024-44817HIGH8.8SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the ...
CVE-2024-43405HIGH7.8Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2,...
CVE-2024-43402HIGH8.8Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments ...
CVE-2024-8418HIGH7.5A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP ...
CVE-2024-8410HIGH7.5A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown...
CVE-2024-8409HIGH7.5A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part ...
CVE-2024-45506HIGH7.5HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2...
CVE-2024-7834HIGH7.8A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-...
CVE-2024-7870HIGH7.5The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable ...
CVE-2024-45195HIGH7.5Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Us...
CVE-2024-8102HIGH8.8The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-34660HIGH7.8Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary c...
CVE-2024-34658HIGH7.1Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
CVE-2024-34656HIGH7.8Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
CVE-2024-34638HIGH7.1Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to del...
CVE-2024-39921HIGH7.5Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF040...
CVE-2024-45450HIGH7.5Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now