2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-3043HIGH7.5An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their net...
CVE-2024-5548HIGH7.5A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-pro...
CVE-2024-5547HIGH7.5A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository,...
CVE-2024-5334HIGH7.5A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerabili...
CVE-2024-31916HIGH7.5IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho...
CVE-2024-24792HIGH7.5Parsing a corrupt or malicious image with invalid color indices can cause a panic.
CVE-2024-39373HIGH7.2TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings ...
CVE-2024-39158HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mud...
CVE-2024-39154HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud...
CVE-2024-22232HIGH7.7A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user ca...
CVE-2024-6054HIGH8.8The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2024-6323HIGH7.5Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior t...
CVE-2024-5655HIGH8.8An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 p...
CVE-2024-28982HIGH8.2Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly...
CVE-2024-36829HIGH7.5Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted que...
CVE-2024-23767HIGH8.8An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated ch...
CVE-2024-23766HIGH7.5An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An u...
CVE-2024-33329HIGH7.5A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access interna...
CVE-2024-6354HIGH7.2Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows a...
CVE-2024-4758HIGH7.6The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, whi...
CVE-2024-34581HIGH7.3The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a ...
CVE-2024-37140HIGH8.8Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection v...
CVE-2024-29176HIGH8.8Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A ...
CVE-2024-5460HIGH8.1A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric...
CVE-2024-38526HIGH7.2pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript fil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now