2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6151HIGH7.8Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows ...
CVE-2024-6148HIGH8.8Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2024-39693HIGH7.5Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can...
CVE-2024-37149HIGH8.8GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2024-37148HIGH8.1GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2024-6235HIGH8.8Sensitive information disclosure in NetScaler Console
CVE-2024-5491HIGH7.5Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
CVE-2024-32469HIGH7.1Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potent...
CVE-2024-37115HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affect...
CVE-2024-37110HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i...
CVE-2024-32759HIGH7.7Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
CVE-2024-3325HIGH7.2Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
CVE-2024-40332HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php...
CVE-2024-40331HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?...
CVE-2024-40334HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?...
CVE-2024-40333HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-40329HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-28828HIGH8.8Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click com...
CVE-2024-28827HIGH7.8Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <=...
CVE-2024-3799HIGH8.7Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec...
CVE-2024-3798HIGH8.7Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project...
CVE-2024-6421HIGH7.5An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic...
CVE-2024-39492HIGH7In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warnin...
CVE-2024-39927HIGH8.2Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted requ...
CVE-2024-36451HIGH8.8Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now