2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45038HIGH7.5Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh net...
CVE-2024-5991HIGH7.5In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and un...
CVE-2024-43783HIGH7.5The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th...
CVE-2024-43414HIGH7.5Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slic...
CVE-2024-42851HIGH7.8Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the p...
CVE-2024-45264HIGH8.8A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote...
CVE-2024-44340HIGH8.8D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_e...
CVE-2024-6632HIGH7.2A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an ...
CVE-2024-8182HIGH7.5An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of ...
CVE-2024-8181HIGH8.1An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attac...
CVE-2024-4872HIGH8.8A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an ...
CVE-2024-3982HIGH8.2An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging suppor...
CVE-2024-3980HIGH8.8The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that ...
CVE-2024-41176HIGH7.3The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Ser...
CVE-2024-41174HIGH7.3The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local att...
CVE-2024-41173HIGH7.8The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged a...
CVE-2024-7125HIGH7.8Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common S...
CVE-2024-45321HIGH8.1The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network...
CVE-2024-43798HIGH8.6Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documen...
CVE-2024-43916HIGH7.1Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects ...
CVE-2024-43325HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP...
CVE-2024-43287HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendin...
CVE-2024-43264HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.T...
CVE-2024-43259HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in WebFactory Order Export for WooCommerce order-export-...
CVE-2024-43258HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now