2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34329HIGH8.4Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch al...
CVE-2024-40634HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i...
CVE-2024-40051HIGH7.5IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.
CVE-2024-41829HIGH7.5In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
CVE-2024-41132HIGH7.5ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially...
CVE-2024-41131HIGH7.5ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo...
CVE-2024-32484HIGH8.2An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp...
CVE-2024-26020HIGH8.8An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted...
CVE-2024-41320HIGH8.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41317HIGH8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-39601HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste...
CVE-2024-25638HIGH8.9dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, al...
CVE-2024-38788HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bởi Admin 2020 UiP...
CVE-2024-38755HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento Dire...
CVE-2024-38708HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of ...
CVE-2024-38701HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a t...
CVE-2024-38692HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spi...
CVE-2024-37942HIGH7.2Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5...
CVE-2024-23321HIGH8.8For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to...
CVE-2024-37436HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl...
CVE-2024-37391HIGH7.8ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{au...
CVE-2024-6244HIGH8.8The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attack...
CVE-2024-5973HIGH8.8The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor ...
CVE-2024-6969HIGH7.5A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This i...
CVE-2024-6968HIGH7.5A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as critical. Thi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now