2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5194HIGH7.2A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an...
CVE-2024-4157HIGH8.8The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner...
CVE-2024-32988HIGH7.5'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded...
CVE-2024-4443HIGH7.5The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based ...
CVE-2024-0453HIGH7.7The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0452HIGH7.7The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-21683HIGH8.8This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and...
CVE-2024-5040HIGH8.5There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.
CVE-2024-35220HIGH7.4@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from th...
CVE-2024-31756HIGH7.8An issue in MarvinTest Solutions Hardware Access Driver v.5.0.3.0 and before and fixed in v.5.0.4.0 allows a local attac...
CVE-2024-35061HIGH7.3NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to...
CVE-2024-35060HIGH7.5An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying...
CVE-2024-35059HIGH7.5An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.
CVE-2024-25724HIGH7.3In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Rec...
CVE-2024-35058HIGH7.5An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a cra...
CVE-2024-35057HIGH7.5An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.
CVE-2024-31757HIGH7.8An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to...
CVE-2024-22274HIGH7.2The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative ...
CVE-2024-22273HIGH7.8The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious...
CVE-2024-36052HIGH7.5RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a differen...
CVE-2024-27130HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-27129HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-27128HIGH8.8A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-27127HIGH8.8A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner...
CVE-2024-21902HIGH8.1An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now