2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7013HIGH7.8Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execut...
CVE-2024-6508HIGH8An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit gr...
CVE-2024-38305HIGH7.3Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the install...
CVE-2024-43882HIGH7In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid...
CVE-2024-43881HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping re...
CVE-2024-43878HIGH7.1In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When ther...
CVE-2024-43877HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In ...
CVE-2024-43873HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow The...
CVE-2024-22281HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacke...
CVE-2024-43403HIGH8.8Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, ...
CVE-2024-42363HIGH8.8Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController....
CVE-2024-42362HIGH8.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe dese...
CVE-2024-41657HIGH8.8Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earli...
CVE-2024-41659HIGH8.1memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier wh...
CVE-2024-31842HIGH8.8An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user ...
CVE-2024-42619HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-38175HIGH8.8An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta...
CVE-2024-42612HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-35214HIGH7.1A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3....
CVE-2024-27187HIGH7.5Improper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2024-43406HIGH8.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2024-42662HIGH7.5An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVE-2024-42621HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php
CVE-2024-42618HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karm...
CVE-2024-42617HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now