2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-55019HIGH7.5Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310...
CVE-2024-31328HIGH8.8In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from ...
CVE-2024-47886HIGH7.2Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a...
CVE-2024-48928HIGH7.5Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec...
CVE-2024-56373HIGH8.4DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb...
CVE-2024-1524HIGH8.1When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ...
CVE-2024-43178HIGH7.5IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2024-55270HIGH8.8phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata...
CVE-2024-50619HIGH8.8Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es...
CVE-2024-50617HIGH7.5Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to...
CVE-2024-50620HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon...
CVE-2024-26480HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p...
CVE-2024-26477HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par...
CVE-2024-36324HIGH8.8Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia...
CVE-2024-36320HIGH7Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to ...
CVE-2024-56808HIGH7.8A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network...
CVE-2024-36355HIGH7Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec...
CVE-2024-5386HIGH8.8In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ...
CVE-2024-54263HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-4027HIGH7.5A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an...
CVE-2024-11976HIGH7.3The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ...
CVE-2024-44238HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1...
CVE-2024-48077HIGH7.5NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of reque...
CVE-2024-58340HIGH7.5LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the...
CVE-2024-58339HIGH7.5LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now