2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-26026HIGH7.5An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have ...
CVE-2024-25560HIGH7.5 When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM)...
CVE-2024-25526HIGH8.1RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /Proje...
CVE-2024-25515HIGH7.3RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ...
CVE-2024-21793HIGH7.5An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which hav...
CVE-2024-31270HIGH8Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: ...
CVE-2024-24833HIGH8.8Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects...
CVE-2024-1438HIGH7.7Missing Authorization vulnerability in PressFore Rolo Slider.This issue affects Rolo Slider: from n/a through 1.0.9.
CVE-2024-3507HIGH7.7Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerabil...
CVE-2024-4438HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487...
CVE-2024-4437HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue oc...
CVE-2024-4436HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue oc...
CVE-2024-22264HIGH7.2VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMwar...
CVE-2024-2860HIGH7.8The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authenticatio...
CVE-2024-2746HIGH8.8Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary confi...
CVE-2024-1929HIGH8.4Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Co...
CVE-2024-4030HIGH7.1On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ...
CVE-2024-27273HIGH7.8IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose app...
CVE-2024-23713HIGH7.8In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications se...
CVE-2024-23710HIGH7.8In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary ap...
CVE-2024-23708HIGH7.8In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a cli...
CVE-2024-23707HIGH7.8In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local...
CVE-2024-23706HIGH7.8In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This c...
CVE-2024-23705HIGH7.8In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validat...
CVE-2024-23704HIGH7.8In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now