2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43403HIGH8.8Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, ...
CVE-2024-42363HIGH8.8Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController....
CVE-2024-42362HIGH8.8Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe dese...
CVE-2024-41657HIGH8.8Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earli...
CVE-2024-41659HIGH8.1memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier wh...
CVE-2024-31842HIGH8.8An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user ...
CVE-2024-42619HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-38175HIGH8.8An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta...
CVE-2024-42612HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-35214HIGH7.1A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3....
CVE-2024-27187HIGH7.5Improper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2024-43406HIGH8.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2024-42662HIGH7.5An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVE-2024-42621HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php
CVE-2024-42618HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karm...
CVE-2024-42617HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php...
CVE-2024-42616HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.ph...
CVE-2024-42613HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.ph...
CVE-2024-42611HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=d...
CVE-2024-42610HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php...
CVE-2024-42609HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php...
CVE-2024-42607HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php...
CVE-2024-42606HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?cl...
CVE-2024-42605HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?li...
CVE-2024-42604HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now