2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38209HIGH7.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-8083HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0...
CVE-2024-45201HIGH8.8An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_nam...
CVE-2024-42599HIGH8.8SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.ph...
CVE-2024-42418HIGH7.5Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
CVE-2024-39776HIGH7.5Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
CVE-2024-8088HIGH8.7There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the mo...
CVE-2024-39717HIGH7.2The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only avai...
CVE-2024-42767HIGH7.2Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
CVE-2024-42776HIGH7.2Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
CVE-2024-42774HIGH7.5An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,...
CVE-2024-42772HIGH7.5An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which...
CVE-2024-42490HIGH7.5authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica...
CVE-2024-36444HIGH8.1cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device...
CVE-2024-36442HIGH8.8cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar...
CVE-2024-36443HIGH7.6Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym...
CVE-2024-39745HIGH7.5IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that ...
CVE-2024-8071HIGH7.2Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can...
CVE-2024-40886HIGH8.8Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the...
CVE-2024-7384HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2024-39576HIGH8.8Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low pri...
CVE-2024-43033HIGH8.8JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via...
CVE-2024-7980HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7979HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...
CVE-2024-7977HIGH7.8Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now