2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54013HIGH8.8Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server co...
CVE-2024-8010HIGH7.5The component accepts XML input through the publisher without disabling external entity resolution. This allows maliciou...
CVE-2024-53412HIGH8.4Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel...
CVE-2024-33618HIGH7.5Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv...
CVE-2024-1490HIGH7.2An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management...
CVE-2024-14032HIGH8.5Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that ...
CVE-2024-14033HIGH8.7Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. A...
CVE-2024-44303HIGH7.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be ...
CVE-2024-44286HIGH7.5This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with ...
CVE-2024-44250HIGH8.2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-44219HIGH7.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a...
CVE-2024-40858HIGH7.1A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-40849HIGH7.5A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able...
CVE-2024-14031HIGH8.1Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-14030HIGH8.1Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-11604HIGH7.3Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Exte...
CVE-2024-58341HIGH8.2OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate databas...
CVE-2024-51348HIGH8.8A stack-based buffer overflow vulnerability in the P2P API service in BS Producten Petcam with firmware 33.1.0.0818 allo...
CVE-2024-51347HIGH7.2A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handli...
CVE-2024-51346HIGH7.7An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptograph...
CVE-2024-32537HIGH7.1Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This...
CVE-2024-14026HIGH7.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai...
CVE-2024-55027HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_...
CVE-2024-55022HIGH8.8Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerabi...
CVE-2024-55021HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now