2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-41692HIGH8.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte...
CVE-2024-7062HIGH7.8Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged...
CVE-2024-41687HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ...
CVE-2024-41685HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass...
CVE-2024-35296HIGH8.2Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This...
CVE-2024-35161HIGH7.5Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for reques...
CVE-2024-7119HIGH8.8A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System u...
CVE-2024-7118HIGH8.8A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Af...
CVE-2024-7117HIGH8.8A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 2023091...
CVE-2024-7116HIGH8.8A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as crit...
CVE-2024-7115HIGH8.8A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as c...
CVE-2024-7114HIGH8.8A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part...
CVE-2024-24623HIGH8.8Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticat...
CVE-2024-24622HIGH8.8Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker ca...
CVE-2024-7106HIGH8.8A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown fu...
CVE-2024-7105HIGH8.8A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown...
CVE-2024-38288HIGH7.2A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow...
CVE-2024-29069HIGH7.3In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap...
CVE-2024-40318HIGH7.2An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploadi...
CVE-2024-1724HIGH8.2In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w...
CVE-2024-41800HIGH7.5Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity p...
CVE-2024-40872HIGH8.4There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to vers...
CVE-2024-36542HIGH8.8Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the s...
CVE-2024-7101HIGH7.3A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue...
CVE-2024-39673HIGH7.1Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now