2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12483MEDIUM5.9A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t...
CVE-2024-12482MEDIUM4.3A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is th...
CVE-2024-12481HIGH8.8A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerabili...
CVE-2024-12480HIGH8.8A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been classified as critical. Affected is the function s...
CVE-2024-12479HIGH8.8A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function sea...
CVE-2024-12382HIGH8.8Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit he...
CVE-2024-12381HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-11950HIGH8.8XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-11949HIGH8.8GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-11948CRITICAL9.8GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a...
CVE-2024-11947HIGH8.8GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-11872HIGH7.8Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo...
CVE-2024-9845HIGH7.8Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent...
CVE-2024-8496HIGH7.8Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local ...
CVE-2024-48912HIGH8.1GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut...
CVE-2024-47761HIGH7.2GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin...
CVE-2024-47760HIGH8.8GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn...
CVE-2024-11598HIGH7.8Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, ...
CVE-2024-11597HIGH7.8Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, ...
CVE-2024-10251HIGH7.8Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local au...
CVE-2024-53677CRITICAL9.8File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an...
CVE-2024-47758HIGH8.8GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an auth...
CVE-2024-28141MEDIUM6.3The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users ...
CVE-2024-28140MEDIUM6.1The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser...
CVE-2024-28139HIGH8.8The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as r...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now