2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23365HIGH8.4Memory corruption while releasing shared resources in MinkSocket listener thread.
CVE-2024-23364HIGH7.5Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme...
CVE-2024-23362HIGH7.1Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359HIGH8.2Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23358HIGH7.5Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-7871HIGH8.7SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti...
CVE-2024-43776HIGH8.8SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us...
CVE-2024-43775HIGH8.8SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe...
CVE-2024-43774HIGH8.8SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow...
CVE-2024-41160HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-41157HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-39816HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2024-39775HIGH7.5in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
CVE-2024-38386HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2024-20089HIGH7.5In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of serv...
CVE-2024-7717HIGH8.8The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all ve...
CVE-2024-0110HIGH7.8NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by pass...
CVE-2024-44945HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use ...
CVE-2024-7435HIGH8.8The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des...
CVE-2024-6586HIGH7.3Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s...
CVE-2024-38868HIGH8.3Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.Thi...
CVE-2024-8344HIGH8.8A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this ...
CVE-2024-6204HIGH8.1Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
CVE-2024-8342HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This ...
CVE-2024-44916HIGH7.2Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are writt...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now