2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31977HIGH8.8Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s...
CVE-2024-22443HIGH8.8A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2024-7067HIGH8.8A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ...
CVE-2024-6197HIGH7.5libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi...
CVE-2024-39676HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin...
CVE-2024-7027HIGH7.3The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ...
CVE-2024-6756HIGH8.8The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2024-6750HIGH7.5The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ...
CVE-2024-38176HIGH8.1An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri...
CVE-2024-38164HIGH8.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-0981HIGH7.1Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T...
CVE-2024-41668HIGH8.3The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se...
CVE-2024-41178HIGH7.5Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e...
CVE-2024-6714HIGH7.8An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th...
CVE-2024-4076HIGH7.5Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result...
CVE-2024-41655HIGH7.5TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4...
CVE-2024-40060HIGH7.5go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
CVE-2024-1975HIGH7.5If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from...
CVE-2024-1737HIGH7.5Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYP...
CVE-2024-0760HIGH7.5A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the atta...
CVE-2024-5602HIGH7.8A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitra...
CVE-2024-4081HIGH7.8A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary ...
CVE-2024-4080HIGH7.8A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in ar...
CVE-2024-4079HIGH7.8An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code exec...
CVE-2024-7014HIGH8.1EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now