2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4748HIGH7.8The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application serve...
CVE-2024-39291HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_ cp_...
CVE-2024-38667HIGH7.8In the Linux kernel, the following vulnerability has been resolved: riscv: prevent pt_regs corruption for secondary idl...
CVE-2024-38664HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_dpsub: Always register bridge We must ...
CVE-2024-38384HIGH7.8In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRI...
CVE-2024-34027HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_comp...
CVE-2024-5862HIGH7.5Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication...
CVE-2024-37111HIGH7.5Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from ...
CVE-2024-37109HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows ...
CVE-2024-37107HIGH8.8Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This is...
CVE-2024-37092HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin...
CVE-2024-37091HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Cons...
CVE-2024-36496HIGH7.5The configuration file is encrypted with a static key derived from a static five-character password which allows an att...
CVE-2024-36495HIGH7.7The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file syst...
CVE-2024-24554HIGH8.2Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the A...
CVE-2024-24553HIGH7.5Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords ...
CVE-2024-24552HIGH8.8A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an...
CVE-2024-24551HIGH8.8A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code throu...
CVE-2024-24550HIGH8.1A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arb...
CVE-2024-6279HIGH8.8A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by...
CVE-2024-6278HIGH8.8A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affect...
CVE-2024-6277HIGH8.8A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Aff...
CVE-2024-6276HIGH8.8A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1...
CVE-2024-6275HIGH8.8A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerabil...
CVE-2024-6274HIGH8.8A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now