2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42038HIGH7.8Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-42036HIGH7.5Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability...
CVE-2024-42035HIGH7.8Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may a...
CVE-2024-42033HIGH7.1Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability wi...
CVE-2024-42257HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with...
CVE-2024-42031HIGH7.5Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerabili...
CVE-2024-22069HIGH8.8There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissi...
CVE-2024-7150HIGH8.8The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id...
CVE-2024-6869HIGH7.1The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-7492HIGH8.8The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-7561HIGH8.8The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d...
CVE-2024-7560HIGH7.2The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via...
CVE-2024-7486HIGH8.8The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v...
CVE-2024-38202HIGH7.3Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli...
CVE-2024-6893HIGH7.5The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all...
CVE-2024-6891HIGH8.8Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login ...
CVE-2024-6890HIGH8.8Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ...
CVE-2024-6707HIGH8.8Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver...
CVE-2024-7143HIGH8.3A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permission...
CVE-2024-7061HIGH7.8Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta ...
CVE-2024-20451HIGH7.5Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco...
CVE-2024-41309HIGH7.8An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted termina...
CVE-2024-41308HIGH7.8An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal enviro...
CVE-2024-42005HIGH7.3An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on...
CVE-2024-41991HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now