2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-32860HIGH8.2Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...
CVE-2024-32859HIGH8.2Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...
CVE-2024-32858HIGH8.2Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi...
CVE-2024-34129HIGH7.5Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a ...
CVE-2024-34116HIGH7.1Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability ...
CVE-2024-34115HIGH7.8Substance3D - Stager versions 2.1.4 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2024-34112HIGH7.5ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could resu...
CVE-2024-20753HIGH7.8Photoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a c...
CVE-2024-34111HIGH8.8Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (S...
CVE-2024-34110HIGH7.2Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File w...
CVE-2024-34109HIGH7.2Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vul...
CVE-2024-34108HIGH7.2Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vul...
CVE-2024-34104HIGH8.2Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulner...
CVE-2024-34103HIGH8.1Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulne...
CVE-2024-4145HIGH7.2The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2024-2098HIGH7.5The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization ...
CVE-2024-3468HIGH8.4There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment un...
CVE-2024-3467HIGH7.8There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System ...
CVE-2024-37665HIGH8.8An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator vi...
CVE-2024-5798HIGH7.5Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the V...
CVE-2024-2747HIGH7.8CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation ...
CVE-2024-0865HIGH7.8CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in a...
CVE-2024-5908HIGH7.5A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for c...
CVE-2024-5907HIGH7A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local ...
CVE-2024-5560HIGH7.5CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now