2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-21918HIGH7.8 A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user...
CVE-2024-21913HIGH7.8 A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially al...
CVE-2024-21912HIGH7.8 An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert una...
CVE-2024-23722HIGH7.5In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content...
CVE-2024-23482HIGH7.8The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fi...
CVE-2024-2891HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuic...
CVE-2024-30235HIGH8.8Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page G...
CVE-2024-30234HIGH8.8Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
CVE-2024-1933HIGH7.1Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an atta...
CVE-2024-30231HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is...
CVE-2024-28093HIGH8.8The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for ...
CVE-2024-24799HIGH8.8Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: fro...
CVE-2024-2904HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through ...
CVE-2024-28131HIGH7.8EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer,...
CVE-2024-28033HIGH7.3OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker...
CVE-2024-29195HIGH8.1The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used ...
CVE-2024-29189HIGH7.8PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ans...
CVE-2024-0866HIGH8.1The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and in...
CVE-2024-29302HIGH7.5SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.
CVE-2024-29301HIGH7.5SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=
CVE-2024-1973HIGH8.5By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to ele...
CVE-2024-2427HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling i...
CVE-2024-2426HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ...
CVE-2024-2425HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ...
CVE-2024-29515HIGH8.8File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now