2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-50696HIGH7.5SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a speci...
CVE-2024-50691HIGH7.4SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app expli...
CVE-2024-53427HIGH8.1decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha...
CVE-2024-47053HIGH7.7This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c...
CVE-2024-39441HIGH8.4In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no ...
CVE-2024-13633HIGH7.1The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13632HIGH7.1The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13631HIGH7.1The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-13624HIGH7.1The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13571HIGH7.1The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-12878HIGH7.1The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-10483HIGH7.1The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-10152HIGH7.1The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before ou...
CVE-2024-0148HIGH7.6NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged ...
CVE-2024-45424HIGH7.5Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of informatio...
CVE-2024-45421HIGH8.8Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network acce...
CVE-2024-45418HIGH8.8Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to ...
CVE-2024-12368HIGH8.8Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user...
CVE-2024-12918HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea...
CVE-2024-12917HIGH8.3Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre...
CVE-2024-12916HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif...
CVE-2024-55898HIGH8.5IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri...
CVE-2024-52939HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2024-46975HIGH7.9Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data in...
CVE-2024-12577HIGH7.3Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now