2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39937HIGH7.5supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.
CVE-2024-39935HIGH8.8jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated u...
CVE-2024-39934HIGH7.8Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup ...
CVE-2024-39933HIGH7.7Gogs through 0.13.0 allows argument injection during the tagging of a new release.
CVE-2024-6506HIGH8.2Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This ...
CVE-2024-6507HIGH8.1Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
CVE-2024-5943HIGH8.8The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-6319HIGH8.8The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u...
CVE-2024-6318HIGH8.8The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u...
CVE-2024-3904HIGH8.8Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-V...
CVE-2024-1182HIGH7Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-2385HIGH8.8The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-38345HIGH8.1A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is...
CVE-2024-6284HIGH7.3In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables conf...
CVE-2024-34750HIGH7.5Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When proc...
CVE-2024-33871HIGH8.8An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution v...
CVE-2024-29511HIGH7.5Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrar...
CVE-2024-35227HIGH7.5Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o...
CVE-2024-29509HIGH8.8Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the ...
CVE-2024-29506HIGH8.8Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF ...
CVE-2024-6471HIGH8.8A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affe...
CVE-2024-5672HIGH7.2A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization ...
CVE-2024-6427HIGH7.5Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u...
CVE-2024-6426HIGH7.1Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacke...
CVE-2024-6469HIGH8.8A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now