2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-28287HIGH7.3A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect use...
CVE-2024-22248HIGH7.1VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim ...
CVE-2024-22246HIGH7.4VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execut...
CVE-2024-30248HIGH7.7Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel...
CVE-2024-30965HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php...
CVE-2024-29514HIGH8.8File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload...
CVE-2024-29949HIGH7.2There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administr...
CVE-2024-31005HIGH8.1An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_Mdhd...
CVE-2024-31003HIGH8.8Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4...
CVE-2024-29074HIGH8.8in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper in...
CVE-2024-28951HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u...
CVE-2024-28226HIGH7.5in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.
CVE-2024-26674HIGH7.1In the Linux kernel, the following vulnerability has been resolved: x86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_...
CVE-2024-26673HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: sanitize layer 3 and 4 protocol ...
CVE-2024-26672HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix variable 'mca_funcs' dereferenced b...
CVE-2024-26669HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: Fix chain template offload When...
CVE-2024-26666HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix RCU use in TDLS fast-xmit This...
CVE-2024-26665HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv...
CVE-2024-26664HIGH7.1In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix out-of-bounds memory access ...
CVE-2024-24581HIGH7.8in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.
CVE-2024-22098HIGH8.8in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through use after f...
CVE-2024-22092HIGH7.4in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, althoug...
CVE-2024-25187HIGH8.6Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sens...
CVE-2024-20849HIGH7.8Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 all...
CVE-2024-20848HIGH7.8Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now