2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37110HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i...
CVE-2024-32759HIGH7.7Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
CVE-2024-3325HIGH7.2Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
CVE-2024-40332HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php...
CVE-2024-40331HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?...
CVE-2024-40334HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?...
CVE-2024-40333HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-40329HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-28828HIGH8.8Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click com...
CVE-2024-28827HIGH7.8Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <=...
CVE-2024-3799HIGH8.7Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec...
CVE-2024-3798HIGH8.7Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project...
CVE-2024-6421HIGH7.5An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic...
CVE-2024-39492HIGH7In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warnin...
CVE-2024-39927HIGH8.2Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted requ...
CVE-2024-36451HIGH8.8Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2...
CVE-2024-6411HIGH8.8The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in al...
CVE-2024-39614HIGH7.5An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject t...
CVE-2024-38875HIGH7.5An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a poten...
CVE-2024-21526HIGH7.5All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to t...
CVE-2024-21525HIGH8.3All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the...
CVE-2024-21523HIGH7.5All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to ...
CVE-2024-21522HIGH7.5All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to th...
CVE-2024-21521HIGH7.5All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object w...
CVE-2024-38301HIGH7.8Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now