2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45338MEDIUM5.3An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, r...
CVE-2024-12686HIGH7.2A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacke...
CVE-2024-53271HIGH7.1Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle...
CVE-2024-53270HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to...
CVE-2024-53269HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then t...
CVE-2024-52593MEDIUM5.3Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService...
CVE-2024-52592MEDIUM5.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u...
CVE-2024-52591CRITICAL9.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-52590MEDIUM6.5Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-52579MEDIUM5.4Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t...
CVE-2024-51470MEDIUM6.5IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE...
CVE-2024-49363HIGH7.4Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in gith...
CVE-2024-36694HIGH7.2OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
CVE-2024-12741HIGH8.4A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Succ...
CVE-2024-56057HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56055HIGH8.8Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM...
CVE-2024-56054HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56053HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w...
CVE-2024-56052HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56051HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Inj...
CVE-2024-56050HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56049HIGH8.5Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM...
CVE-2024-56048HIGH8.8Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra...
CVE-2024-56047HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w...
CVE-2024-55953HIGH8.1DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now