2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-32394HIGH8.8An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1...
CVE-2024-32399HIGH7.6Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensi...
CVE-2024-32407HIGH8.8An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to t...
CVE-2024-28699HIGH7.8A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::cop...
CVE-2024-32368HIGH7.3Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta...
CVE-2024-22811HIGH8.2An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b...
CVE-2024-22808HIGH7.5An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b...
CVE-2024-32684HIGH7.5Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through ...
CVE-2024-32682HIGH8.8Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad...
CVE-2024-32681HIGH8.8Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad...
CVE-2024-32695HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Languag...
CVE-2024-32694HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interacti...
CVE-2024-32693HIGH7.6Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3....
CVE-2024-4020HIGH8.8A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function from...
CVE-2024-1480HIGH7.5Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authenticatio...
CVE-2024-4018HIGH7.8Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api mo...
CVE-2024-4017HIGH7.8Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) al...
CVE-2024-32391HIGH7.3Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code vi...
CVE-2024-30974HIGH7.3SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId paramete...
CVE-2024-22905HIGH7Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted s...
CVE-2024-32652HIGH7.5The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs...
CVE-2024-31552HIGH7.1CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitr...
CVE-2024-32650HIGH7.5Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop...
CVE-2024-32409HIGH7.1An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-31846HIGH7.5An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now