2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5622HIGH7.8An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may...
CVE-2024-43700HIGH7.8xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-ba...
CVE-2024-45436HIGH7.5extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct...
CVE-2024-8198HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ...
CVE-2024-8194HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-8193HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ...
CVE-2024-45059HIGH8.8i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators...
CVE-2024-45058HIGH8.1i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators...
CVE-2024-44760HIGH7.5Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0...
CVE-2024-42793HIGH8A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted requ...
CVE-2024-41236HIGH7.2A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an...
CVE-2024-7745HIGH8.1In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra...
CVE-2024-20478HIGH7.2A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco...
CVE-2024-20446HIGH8.6A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cau...
CVE-2024-20286HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-20285HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-20284HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-5546HIGH8.8Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affect...
CVE-2024-6311HIGH7.2The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-4556HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Ma...
CVE-2024-4555HIGH7.5Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif...
CVE-2024-45346HIGH8.8The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend M...
CVE-2024-39584HIGH8.2Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with lo...
CVE-2024-8231HIGH8.8A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet...
CVE-2024-45049HIGH7.5Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now