2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31851HIGH8.6A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jett...
CVE-2024-31850HIGH8.6A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty...
CVE-2024-22004HIGH7.7Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability...
CVE-2024-31220HIGH7.3Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an att...
CVE-2024-31083HIGH7.8A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when A...
CVE-2024-26810HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask oper...
CVE-2024-3217HIGH8.8The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' pa...
CVE-2024-30891HIGH8.8A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to con...
CVE-2024-2115HIGH8.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2024-29863HIGH7.8A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR...
CVE-2024-29672HIGH8.8Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code v...
CVE-2024-22363HIGH7.5SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
CVE-2024-31498HIGH8.8Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation b...
CVE-2024-31212HIGH7.2InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2...
CVE-2024-31210HIGH8.8WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be sub...
CVE-2024-31206HIGH8.2dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to th...
CVE-2024-3316HIGH8.8A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical....
CVE-2024-3311HIGH8.8A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability...
CVE-2024-30255HIGH7.5Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3...
CVE-2024-29387HIGH8.8projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/pri...
CVE-2024-27316HIGH7.5HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP...
CVE-2024-22053HIGH8.2A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an...
CVE-2024-22052HIGH7.5A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secur...
CVE-2024-30249HIGH8.6Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2024-25007HIGH7.1 Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now