2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27801HIGH7.8The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 1...
CVE-2024-37393HIGH7.5Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl...
CVE-2024-36416HIGH7.5SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-36415HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-36411HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-23299HIGH8.6The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ven...
CVE-2024-22279HIGH7.5Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrad...
CVE-2024-36410HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-36409HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-5102HIGH7A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privile...
CVE-2024-36408HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-35745HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Gabriel Somoza / Joseph ...
CVE-2024-37051HIGH7.5GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ...
CVE-2024-35650HIGH7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-34800HIGH7.6Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorr...
CVE-2024-34761HIGH8.5Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection...
CVE-2024-34332HIGH7.8An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a c...
CVE-2024-26507HIGH7.8An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allow...
CVE-2024-4403HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9...
CVE-2024-36972HIGH7.8In the Linux kernel, the following vulnerability has been resolved: af_unix: Update unix_sk(sk)->oob_skb under sk_recei...
CVE-2024-36528HIGH8.8nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in co...
CVE-2024-5785HIGH8Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerab...
CVE-2024-36405HIGH7.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co...
CVE-2024-28833HIGH7.5Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2...
CVE-2024-36971HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now