2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39890HIGH8.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108...
CVE-2024-53900CRITICAL9.1Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
CVE-2024-39343HIGH7An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 24...
CVE-2024-5890MEDIUM5.1ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability cou...
CVE-2024-53617MEDIUM4.8A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl...
CVE-2024-53484HIGH8.8Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key.
CVE-2024-52724CRITICAL9.8ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.
CVE-2024-53990CRITICAL9.2The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2024-53566MEDIUM5.5An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows...
CVE-2024-53564HIGH7.2A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil...
CVE-2024-53992HIGH8.8unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic...
CVE-2024-53364MEDIUM5.4A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php....
CVE-2024-53259MEDIUM6.5quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet...
CVE-2024-52806HIGH8.3SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, ...
CVE-2024-52596HIGH8.8SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for ...
CVE-2024-50381HIGH8.8A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim ...
CVE-2024-50380HIGH8.7Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can imperso...
CVE-2024-49763HIGH8.7PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensiti...
CVE-2024-53984MEDIUM4.3Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, ...
CVE-2024-53981HIGH7.5python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks ...
CVE-2024-53862HIGH7.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When us...
CVE-2024-53459MEDIUM5.4Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
CVE-2024-8785MEDIUM5.3In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create ...
CVE-2024-52732CRITICAL9.1Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system bei...
CVE-2024-46909CRITICAL9.8In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now