2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7080HIGH7.5A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affect...
CVE-2024-41550HIGH7.2CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice...
CVE-2024-41135HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-41134HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-41133HIGH7.2A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot...
CVE-2024-36534HIGH8.4Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin...
CVE-2024-33519HIGH7.2A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an ...
CVE-2024-40495HIGH8A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute a...
CVE-2024-36538HIGH8.8Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining...
CVE-2024-36537HIGH7.2Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain...
CVE-2024-41672HIGH7.5DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading...
CVE-2024-41667HIGH8.8OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in Re...
CVE-2024-7069HIGH7.5A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi...
CVE-2024-36541HIGH8.8Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt...
CVE-2024-31970HIGH8.8AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default...
CVE-2024-39345HIGH7.2AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,...
CVE-2024-31977HIGH8.8Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s...
CVE-2024-22443HIGH8.8A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2024-7067HIGH8.8A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ...
CVE-2024-6197HIGH7.5libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi...
CVE-2024-39676HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin...
CVE-2024-7027HIGH7.3The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ...
CVE-2024-6756HIGH8.8The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2024-6750HIGH7.5The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ...
CVE-2024-38176HIGH8.1An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now