2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-40479HIGH8.1A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers ...
CVE-2024-40476HIGH8A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. ...
CVE-2024-40475HIGH8.8SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re...
CVE-2024-39815HIGH7.5Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays ...
CVE-2024-39338HIGH7.5axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative...
CVE-2024-38218HIGH7.8Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2024-37826HIGH7.5A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP...
CVE-2024-36462HIGH7.5Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources...
CVE-2024-36461HIGH8.8Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
CVE-2024-36460HIGH8.1The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te...
CVE-2024-36035HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec...
CVE-2024-36034HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report...
CVE-2024-30188HIGH8.1File read and write vulnerability in Apache DolphinScheduler ,  authenticated users can illegally access additional reso...
CVE-2024-29831HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox...
CVE-2024-29082HIGH8.6Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa...
CVE-2024-22116HIGH7.2An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ...
CVE-2024-21881HIGH8.6Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp...
CVE-2024-21880HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ...
CVE-2024-21879HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet...
CVE-2024-0113HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau...
CVE-2024-39287HIGH7.5Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa...
CVE-2024-37382HIGH7.2An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows att...
CVE-2024-0104HIGH8.8NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us...
CVE-2024-42365HIGH8.8Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9...
CVE-2024-0108HIGH8.8NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean u...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now