2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54028HIGH7.8An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra...
CVE-2024-52035HIGH7.8An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. ...
CVE-2024-48877HIGH7.8A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers...
CVE-2024-57783HIGH8.1The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu...
CVE-2024-12168HIGH7.8Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.
CVE-2024-11857HIGH8.5Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat...
CVE-2024-42191CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker ...
CVE-2024-42190CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2024-23589MEDIUM6.8Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dic...
CVE-2024-13917HIGH8.3An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-13916MEDIUM6.9An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any applicati...
CVE-2024-13915MEDIUM6.9Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preload...
CVE-2024-7097MEDIUM4.3An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which...
CVE-2024-7096MEDIUM5.4A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin service...
CVE-2024-12224HIGH8.8Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create...
CVE-2024-54952HIGH7.5MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers ...
CVE-2024-49350HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12....
CVE-2024-53423MEDIUM5.6An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafte...
CVE-2024-51392HIGH8.8An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the ...
CVE-2024-22654HIGH7.5tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
CVE-2024-22653MEDIUM4.8yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at se...
CVE-2024-52588HIGH7.5Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks ...
CVE-2024-57338MEDIUM6.5An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x...
CVE-2024-57337MEDIUM6.5An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.10...
CVE-2024-57336MEDIUM6.5Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unautho...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now