2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31525HIGH7.2Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to eleva...
CVE-2024-53458HIGH7.5Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packe...
CVE-2024-11216HIGH7.6Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vuln...
CVE-2024-13471HIGH7.5The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2024-13232HIGH8.8The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitra...
CVE-2024-0114HIGH8.1NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious a...
CVE-2024-10930HIGH7.8An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking an...
CVE-2024-9149HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Comme...
CVE-2024-50705HIGH7.1Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote at...
CVE-2024-48248HIGH8.6NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /...
CVE-2024-47259HIGH7.1Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a ...
CVE-2024-51962HIGH8.7A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that cou...
CVE-2024-51961HIGH7.5There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated a...
CVE-2024-51954HIGH8.5There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under uni...
CVE-2024-53388HIGH8.8A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML el...
CVE-2024-53387HIGH8.8A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTM...
CVE-2024-45782HIGH7.8A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver ...
CVE-2024-41771HIGH7.5IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download tempo...
CVE-2024-41770HIGH7.5IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download tempo...
CVE-2024-8261HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Conf...
CVE-2024-53034HIGH7.8Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed wit...
CVE-2024-53033HIGH7.8Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer addr...
CVE-2024-53032HIGH7Memory corruption may occur in keyboard virtual device due to guest VM interaction.
CVE-2024-53031HIGH7.8Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
CVE-2024-53030HIGH7.8Memory corruption while processing input message passed from FE driver.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now