2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21687HIGH8.1This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and ...
CVE-2024-21686HIGH8.7This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This ...
CVE-2024-6492HIGH7.4Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14....
CVE-2024-40516HIGH8.8An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary ...
CVE-2024-33181HIGH8.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parame...
CVE-2024-6089HIGH7.5An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent...
CVE-2024-40322HIGH8.8An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
CVE-2024-6655HIGH7A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK ap...
CVE-2024-32861HIGH7.8Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission...
CVE-2024-6435HIGH8.8A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privi...
CVE-2024-6457HIGH7.5The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection ...
CVE-2024-40631HIGH8.1Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars...
CVE-2024-36438HIGH7.3eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check...
CVE-2024-36434HIGH7.5An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmw...
CVE-2024-36433HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with...
CVE-2024-36432HIGH7.5An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN mo...
CVE-2024-39819HIGH7.3Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to co...
CVE-2024-27241HIGH7.5Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via ...
CVE-2024-27240HIGH7.8Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a p...
CVE-2024-40560HIGH7.3Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.
CVE-2024-40554HIGH7.5An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.
CVE-2024-6689HIGH7.8Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivil...
CVE-2024-38494HIGH8.6This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P...
CVE-2024-38491HIGH8.4The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.
CVE-2024-6746HIGH8.8A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now