2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37818HIGH8.6Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. ...
CVE-2024-37626HIGH8.8A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrar...
CVE-2024-37676HIGH8.4An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSett...
CVE-2024-6162HIGH7.5A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on t...
CVE-2024-6189HIGH8.8A vulnerability was found in Tenda A301 15.13.08.12. It has been classified as critical. Affected is the function fromSe...
CVE-2024-37532HIGH8.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper...
CVE-2024-6185HIGH8.8A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the fu...
CVE-2024-28147HIGH7.4An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may ...
CVE-2024-29012HIGH7.5Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause De...
CVE-2024-5605HIGH8.8The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter wit...
CVE-2024-3562HIGH8.8The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2....
CVE-2024-3561HIGH8.8The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio...
CVE-2024-6103HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6102HIGH8.8Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially ex...
CVE-2024-6101HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of ...
CVE-2024-6100HIGH8.8Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a ...
CVE-2024-36680HIGH7.5In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The aj...
CVE-2024-36677HIGH7.5In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct ...
CVE-2024-38355HIGH7.3Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket....
CVE-2024-36117HIGH7.5Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem....
CVE-2024-36115HIGH7.1Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem....
CVE-2024-32030HIGH8.1Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka b...
CVE-2024-34444HIGH8.8Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a b...
CVE-2024-22263HIGH8.8Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The...
CVE-2024-38616HIGH8.2In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning Th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now