2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-20891HIGH7.8Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to ...
CVE-2024-20890HIGH8.8Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
CVE-2024-20888HIGH7.8Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activit...
CVE-2024-4836HIGH7.5Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as t...
CVE-2024-37479HIGH8.8Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widge...
CVE-2024-32853HIGH7.8Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A...
CVE-2024-32852HIGH7.5Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerab...
CVE-2024-5767HIGH8.8The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-5606HIGH8.8The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_...
CVE-2024-5349HIGH8.8The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2024-4679HIGH7.8Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNM...
CVE-2024-37765HIGH8.8Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-23736HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to ma...
CVE-2024-32230HIGH7.8FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in...
CVE-2024-32229HIGH8.4FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.
CVE-2024-39249HIGH7.5Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in aut...
CVE-2024-39573HIGH7.5Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules t...
CVE-2024-38477HIGH7.5null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server vi...
CVE-2024-38473HIGH8.1Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be...
CVE-2024-38472HIGH7.5SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and maliciou...
CVE-2024-37298HIGH7.5gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a s...
CVE-2024-36997HIGH8.1In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin...
CVE-2024-36991HIGH7.5In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on t...
CVE-2024-36985HIGH8.8In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or powe...
CVE-2024-36984HIGH8.8In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now