2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4538HIGH7.5IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to...
CVE-2024-4537HIGH7.5IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to...
CVE-2024-4599HIGH7.5Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker t...
CVE-2024-4582HIGH7.3A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknow...
CVE-2024-3759HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.
CVE-2024-3758HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer over...
CVE-2024-27217HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2024-23808HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2024-22472HIGH8.1 A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Re...
CVE-2024-20868HIGH7.1Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung N...
CVE-2024-29941HIGH8Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create ...
CVE-2024-30973HIGH8.8An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code...
CVE-2024-34534HIGH7.3A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0....
CVE-2024-34533HIGH7.3A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x be...
CVE-2024-28725HIGH7.1Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carous...
CVE-2024-33602HIGH7.4nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache ...
CVE-2024-33601HIGH7.3nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup ...
CVE-2024-33599HIGH8.1nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhau...
CVE-2024-33570HIGH8.8Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.
CVE-2024-33118HIGH7.5LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com....
CVE-2024-3661HIGH7.6DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solution...
CVE-2024-34412HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel Parce...
CVE-2024-34386HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Aut...
CVE-2024-34378HIGH8.6Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.
CVE-2024-34369HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now