2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-44250HIGH8.2A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-44219HIGH7.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a...
CVE-2024-40858HIGH7.1A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be...
CVE-2024-40849HIGH7.5A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able...
CVE-2024-14031HIGH8.1Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-14030HIGH8.1Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-11604HIGH7.3Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Exte...
CVE-2024-58341HIGH8.2OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate databas...
CVE-2024-51348HIGH8.8A stack-based buffer overflow vulnerability in the P2P API service in BS Producten Petcam with firmware 33.1.0.0818 allo...
CVE-2024-51347HIGH7.2A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handli...
CVE-2024-51346HIGH7.7An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptograph...
CVE-2024-32537HIGH7.1Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This...
CVE-2024-14026HIGH7.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai...
CVE-2024-55027HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_...
CVE-2024-55022HIGH8.8Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerabi...
CVE-2024-55021HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
CVE-2024-55019HIGH7.5Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310...
CVE-2024-31328HIGH8.8In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from ...
CVE-2024-47886HIGH7.2Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a...
CVE-2024-48928HIGH7.5Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec...
CVE-2024-56373HIGH8.4DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb...
CVE-2024-1524HIGH8.1When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ...
CVE-2024-43178HIGH7.5IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2024-55270HIGH8.8phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata...
CVE-2024-50619HIGH8.8Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now