2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52544CRITICAL9.8An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerabil...
CVE-2024-45676MEDIUM4.3IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf...
CVE-2024-41777HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k...
CVE-2024-41776MEDIUM6.5IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att...
CVE-2024-41775HIGH7.5IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ...
CVE-2024-25020CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted fi...
CVE-2024-53867MEDIUM4.3Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0...
CVE-2024-53863CRITICAL9.1Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option ...
CVE-2024-52815MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ...
CVE-2024-52805HIGH7.5Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf...
CVE-2024-40691CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of ...
CVE-2024-37303MEDIUM5.3Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part...
CVE-2024-37302HIGH7.5Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a...
CVE-2024-29404HIGH7.8An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co...
CVE-2024-25036LOW3.3IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security all...
CVE-2024-25035MEDIUM5.3IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of...
CVE-2024-25019CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of fil...
CVE-2024-54000HIGH7.5Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-53999MEDIUM5.4Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-53257MEDIUM4.9Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt...
CVE-2024-12101Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-11391HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-11200MEDIUM6.1The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter...
CVE-2024-9978MEDIUM5.5in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
CVE-2024-42422HIGH7.5Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now