2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39624HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ...
CVE-2024-39621HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ...
CVE-2024-38791HIGH7.1Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request For...
CVE-2024-38775HIGH7.2Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Fee...
CVE-2024-38768HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elemen...
CVE-2024-38746HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeSto...
CVE-2024-32864HIGH8.1Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
CVE-2024-32863HIGH8.8Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
CVE-2024-7360HIGH8.8A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. Th...
CVE-2024-7256HIGH8.8Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe...
CVE-2024-7255HIGH8.8Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf...
CVE-2024-6990HIGH8.8Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe...
CVE-2024-6873HIGH8.1It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b...
CVE-2024-6242HIGH7.3A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f...
CVE-2024-6040HIGH8.8In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi...
CVE-2024-41265HIGH7.5A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t...
CVE-2024-41264HIGH7.5An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK...
CVE-2024-41260HIGH7.5A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo...
CVE-2024-41946HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity...
CVE-2024-41144HIGH7.1Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post...
CVE-2024-41123HIGH7.5REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has...
CVE-2024-39832HIGH8.7Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error h...
CVE-2024-7358HIGH8.5A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected b...
CVE-2024-28972HIGH7.5Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthentica...
CVE-2024-6529HIGH7.1The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now