2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38456HIGH7.8HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and fo...
CVE-2024-6119HIGH7.5Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte...
CVE-2024-42991HIGH8.1MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-8383HIGH7.5Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that...
CVE-2024-8382HIGH8.8Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for th...
CVE-2024-6232HIGH7.5There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking...
CVE-2024-6473HIGH7.8Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-45588HIGH8.1This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-8374HIGH7.8UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/p...
CVE-2024-45587HIGH8.8This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on A...
CVE-2024-45586HIGH8.8This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Tradi...
CVE-2024-3655HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2024-38811HIGH7.8VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment var...
CVE-2024-7203HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and...
CVE-2024-5412HIGH7.5A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 cou...
CVE-2024-42060HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US...
CVE-2024-42059HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US...
CVE-2024-42058HIGH7.5A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series...
CVE-2024-42057HIGH8.1A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.3...
CVE-2024-1621HIGH7.5The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compr...
CVE-2024-6921HIGH7.5Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev...
CVE-2024-45388HIGH7.5Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap...
CVE-2024-45311HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is...
CVE-2024-42471HIGH7.5actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch ...
CVE-2024-5148HIGH7.5A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now