2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43888HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cg...
CVE-2024-43444HIGH8.2Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations reg...
CVE-2024-45241HIGH7.5A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allow...
CVE-2024-41996HIGH7.5Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is use...
CVE-2024-8147HIGH8.8A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects...
CVE-2024-45240HIGH7.4The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScri...
CVE-2024-45239HIGH7.5An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca...
CVE-2024-45238HIGH7.5An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca...
CVE-2024-45236HIGH7.5An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca...
CVE-2024-45235HIGH7.5An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca...
CVE-2024-45234HIGH7.5An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca...
CVE-2024-7656HIGH8.8The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...
CVE-2024-7351HIGH7.2The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2....
CVE-2024-7568HIGH8.1The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,...
CVE-2024-45187HIGH8.8Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p...
CVE-2024-42845HIGH8An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 al...
CVE-2024-44390HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
CVE-2024-39841HIGH8.8A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, ...
CVE-2024-44386HIGH7.3Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
CVE-2024-42756HIGH8.8An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page
CVE-2024-42636HIGH7.2DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.
CVE-2024-42523HIGH7.2publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CVE-2024-43791HIGH7.8RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 ...
CVE-2024-42915HIGH8A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token...
CVE-2024-42040HIGH8.1Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now