2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7557HIGH8.8A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models w...
CVE-2024-7272HIGH8.8A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio...
CVE-2024-7006HIGH7.5A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me...
CVE-2024-6760HIGH7.5A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it sh...
CVE-2024-5800HIGH7.5Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before...
CVE-2024-5651HIGH8.8A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) pr...
CVE-2024-5527HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing co...
CVE-2024-5487HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a...
CVE-2024-42468HIGH7.5openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C...
CVE-2024-42370HIGH8.3Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-pr...
CVE-2024-42167HIGH7.2The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec...
CVE-2024-42166HIGH7.2The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special...
CVE-2024-42163HIGH8.1Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over t...
CVE-2024-41936HIGH7.5A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software v...
CVE-2024-40488HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lea...
CVE-2024-40487HIGH7.6A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0...
CVE-2024-40479HIGH8.1A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers ...
CVE-2024-40476HIGH8A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. ...
CVE-2024-40475HIGH8.8SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re...
CVE-2024-39815HIGH7.5Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays ...
CVE-2024-39338HIGH7.5axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative...
CVE-2024-38218HIGH7.8Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2024-37826HIGH7.5A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP...
CVE-2024-36462HIGH7.5Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources...
CVE-2024-36461HIGH8.8Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now