2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39182HIGH7.5An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root u...
CVE-2024-33862HIGH7.5A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow...
CVE-2024-5753HIGH7.5vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. T...
CVE-2024-39696HIGH8.1Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can creat...
CVE-2024-39689HIGH7.5Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify...
CVE-2024-39023HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=ad...
CVE-2024-39022HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mud...
CVE-2024-34361HIGH8.8Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vul...
CVE-2024-39687HIGH7.2Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present...
CVE-2024-39321HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability ...
CVE-2024-37903HIGH8.2Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and ...
CVE-2024-37767HIGH7.5Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information v...
CVE-2024-27715HIGH8.2An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27713HIGH8.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27711HIGH8.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-39210HIGH7.5Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page par...
CVE-2024-37769HIGH8.8Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a cra...
CVE-2024-39027HIGH7.5SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through t...
CVE-2024-6525HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as proble...
CVE-2024-6524HIGH8.8A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an ...
CVE-2024-6209HIGH7.5Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series ...
CVE-2024-39480HIGH7.8In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Curre...
CVE-2024-39479HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon an...
CVE-2024-36041HIGH7.8KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ...
CVE-2024-39943HIGH8.8rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now