2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39816HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2024-39775HIGH7.5in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read.
CVE-2024-38386HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o...
CVE-2024-20089HIGH7.5In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of serv...
CVE-2024-7717HIGH8.8The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all ve...
CVE-2024-0110HIGH7.8NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by pass...
CVE-2024-44945HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use ...
CVE-2024-7435HIGH8.8The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des...
CVE-2024-6586HIGH7.3Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s...
CVE-2024-38868HIGH8.3Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.Thi...
CVE-2024-8344HIGH8.8A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this ...
CVE-2024-6204HIGH8.1Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
CVE-2024-8342HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This ...
CVE-2024-44916HIGH7.2Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are writt...
CVE-2024-8338HIGH8.8A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability ...
CVE-2024-8334HIGH8.1A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as p...
CVE-2024-8260HIGH7.3A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability e...
CVE-2024-8252HIGH8.8The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 ...
CVE-2024-8016HIGH7.2The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
CVE-2024-2694HIGH8.8The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d...
CVE-2024-5784HIGH7.1The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ...
CVE-2024-8330HIGH8.86SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula...
CVE-2024-8329HIGH8.86SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit...
CVE-2024-8327HIGH8.8Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p...
CVE-2024-45490HIGH7.5An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now