2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37158HIGH8.1Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the cla...
CVE-2024-36583HIGH8.1A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/a...
CVE-2024-5650HIGH8.5DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an at...
CVE-2024-6045HIGH8.8Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on ...
CVE-2024-6041HIGH8.8A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this ...
CVE-2024-6039HIGH8.8A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of...
CVE-2024-38467HIGH7.5Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API...
CVE-2024-38461HIGH7.5irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.
CVE-2024-38459HIGH7.8langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an o...
CVE-2024-38458HIGH8.8Xenforo before 2.2.16 allows code injection.
CVE-2024-38457HIGH8.8Xenforo before 2.2.16 allows CSRF.
CVE-2024-38440HIGH7.5Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, beca...
CVE-2024-38427HIGH8.8In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in Ic...
CVE-2024-6008HIGH8.8A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an...
CVE-2024-27275HIGH7.8IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req...
CVE-2024-4551HIGH8.8The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi...
CVE-2024-6000HIGH7.1The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp...
CVE-2024-3813HIGH8.8The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8...
CVE-2024-6003HIGH7.3A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been clas...
CVE-2024-36600HIGH8.4Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a craft...
CVE-2024-36598HIGH8.1An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a cra...
CVE-2024-36597HIGH8.8Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
CVE-2024-24320HIGH8.8Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sen...
CVE-2024-37369HIGH8.8A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edi...
CVE-2024-37885HIGH7.8The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now