2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-33383HIGH7.5Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive informatio...
CVE-2024-33332HIGH7.5An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api...
CVE-2024-29384HIGH7.5An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and...
CVE-2024-34088HIGH7.5In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a N...
CVE-2024-28269HIGH7.2ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, le...
CVE-2024-26331HIGH7.5ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind ...
CVE-2024-33831HIGH7.4A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows a...
CVE-2024-23463HIGH8.1Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repa...
CVE-2024-29320HIGH8.1Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
CVE-2024-4340HIGH7.5Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
CVE-2024-33465HIGH7.1Cross Site Scripting vulnerability in MajorDoMo before v.0662e5e allows an attacker to escalate privileges via the the t...
CVE-2024-33309HIGH7.5An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sens...
CVE-2024-33274HIGH7.5Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sens...
CVE-2024-33270HIGH7.5An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive ...
CVE-2024-28716HIGH7.5An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.
CVE-2024-25938HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially craft...
CVE-2024-25648HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially craf...
CVE-2024-25575HIGH8.8A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A spec...
CVE-2024-23774HIGH7.8An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerabi...
CVE-2024-23773HIGH7.8An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability ex...
CVE-2024-2617HIGH7.2A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if se...
CVE-2024-2378HIGH8A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privil...
CVE-2024-2377HIGH7.6A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can tak...
CVE-2024-4337HIGH7.4Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti...
CVE-2024-4336HIGH7.4Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now