2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6901HIGH8.8A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unk...
CVE-2024-6900HIGH8.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affe...
CVE-2024-21527HIGH8.2Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com...
CVE-2024-35199HIGH8.2TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions...
CVE-2024-30130HIGH7.5HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an a...
CVE-2024-41111HIGH7.2Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all s...
CVE-2024-40642HIGH8.1The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class...
CVE-2024-34013HIGH7.8Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True ...
CVE-2024-31143HIGH7.5An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. ...
CVE-2024-29178HIGH8.8On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution...
CVE-2024-40898HIGH7.5SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes t...
CVE-2024-3242HIGH8.8The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension vali...
CVE-2024-40764HIGH7.5Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Den...
CVE-2024-29014HIGH8.8Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an att...
CVE-2024-41011HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page w...
CVE-2024-5726HIGH8.8The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...
CVE-2024-39681HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39680HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39679HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39678HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in version...
CVE-2024-40492HIGH7.1Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the...
CVE-2024-40119HIGH8.8Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (...
CVE-2024-40641HIGH7.4Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way t...
CVE-2024-38447HIGH8.1NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft rep...
CVE-2024-20435HIGH7.8A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to exe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now