2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38453HIGH7.5The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current vers...
CVE-2024-2376HIGH8.8The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-6453HIGH8.8A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this...
CVE-2024-24791HIGH7.5The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" hea...
CVE-2024-6452HIGH8.8A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is a...
CVE-2024-6382HIGH7.5Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. T...
CVE-2024-39894HIGH7.5OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sud...
CVE-2024-39206HIGH7.5An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials ...
CVE-2024-4467HIGH7.8A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `...
CVE-2024-3826HIGH8.6In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On...
CVE-2024-39323HIGH7.1aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions ...
CVE-2024-26314HIGH7.8Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and ...
CVE-2024-25088HIGH7.8Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute...
CVE-2024-25086HIGH7.8Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute...
CVE-2024-22106HIGH7.8Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute ar...
CVE-2024-4897HIGH8.4parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on ll...
CVE-2024-38519HIGH7.8`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-d...
CVE-2024-34122HIGH7.8Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a c...
CVE-2024-34596HIGH7.5Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for...
CVE-2024-34595HIGH7.8Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch...
CVE-2024-34593HIGH8.8Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows re...
CVE-2024-34585HIGH7.8Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privil...
CVE-2024-20901HIGH7.8Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attac...
CVE-2024-20893HIGH7.8Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigg...
CVE-2024-20892HIGH7.8Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now