2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-33615HIGH8.8A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel serve...
CVE-2024-32042HIGH7.5The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, ...
CVE-2024-31856HIGH8.8An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This coul...
CVE-2024-31409HIGH7.5Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtainin...
CVE-2024-4906HIGH7.5A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1....
CVE-2024-35102HIGH8.8Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalat...
CVE-2024-4905HIGH8.8A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown...
CVE-2024-25743HIGH7.1In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and...
CVE-2024-20383HIGH8.4A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager c...
CVE-2024-20366HIGH7.8A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Se...
CVE-2024-4622HIGH8.3If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. I...
CVE-2024-4202HIGH8.6In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an ...
CVE-2024-4200HIGH7.8In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a loca...
CVE-2024-3970HIGH7.5Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senst...
CVE-2024-3485HIGH7.5Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senst...
CVE-2024-28042HIGH8.6SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.
CVE-2024-27353HIGH7.4A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 b...
CVE-2024-25079HIGH7.4A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38...
CVE-2024-25078HIGH7.4A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.2...
CVE-2024-4670HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-34100HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34099HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability ...
CVE-2024-34098HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerabilit...
CVE-2024-34097HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34096HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now