2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6420HIGH8.6The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect W...
CVE-2024-6885HIGH8.1The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file...
CVE-2024-6828HIGH7.2The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization...
CVE-2024-6717HIGH8.6HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to p...
CVE-2024-6913HIGH8.8Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windo...
CVE-2024-6911HIGH7.5Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in P...
CVE-2024-6791HIGH7.8A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote co...
CVE-2024-6675HIGH7.8A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Succ...
CVE-2024-6121HIGH7.8An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including ...
CVE-2024-34329HIGH8.4Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch al...
CVE-2024-40634HIGH7.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i...
CVE-2024-40051HIGH7.5IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.
CVE-2024-41829HIGH7.5In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
CVE-2024-41132HIGH7.5ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially...
CVE-2024-41131HIGH7.5ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo...
CVE-2024-32484HIGH8.2An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp...
CVE-2024-26020HIGH8.8An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted...
CVE-2024-41320HIGH8.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41317HIGH8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-39601HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste...
CVE-2024-25638HIGH8.9dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, al...
CVE-2024-38788HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bởi Admin 2020 UiP...
CVE-2024-38755HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento Dire...
CVE-2024-38708HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of ...
CVE-2024-38701HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now