2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34367HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue...
CVE-2024-33912HIGH8.8Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
CVE-2024-34388HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Scribit GDPR Compliance.This issue affects G...
CVE-2024-33410HIGH8.1SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1....
CVE-2024-33406HIGH7.3SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management...
CVE-2024-33405HIGH8.6SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attac...
CVE-2024-33404HIGH8.3A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management ...
CVE-2024-32807HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for Woo...
CVE-2024-34251HIGH7.5An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a r...
CVE-2024-34246HIGH7.5wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "m...
CVE-2024-34092HIGH8.8An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminat...
CVE-2024-34470HIGH8.6An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability ...
CVE-2024-34252HIGH7.5wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "Pres...
CVE-2024-34069HIGH7.5Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an att...
CVE-2024-33112HIGH7.5D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
CVE-2024-32982HIGH8.2Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a ...
CVE-2024-32972HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable n...
CVE-2024-23354HIGH7.8Memory corruption when the IOCTL call is interrupted by a signal.
CVE-2024-23351HIGH7.8Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
CVE-2024-21477HIGH7.5Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2024-21476HIGH7.8Memory corruption when the channel ID passed by user is not validated and further used.
CVE-2024-21475HIGH7.8Memory corruption when the payload received from firmware is not as per the expected protocol size.
CVE-2024-21474HIGH7.8Memory corruption when size of buffer from previous call is used without validation or re-initialization.
CVE-2024-21471HIGH7.8Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
CVE-2024-4549HIGH7.5A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now