2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24832HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
CVE-2024-2025HIGH8.8The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable ...
CVE-2024-29059HIGH7.5.NET Framework Information Disclosure Vulnerability
CVE-2024-29190HIGH7.5Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-2828HIGH8.8A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the func...
CVE-2024-2827HIGH8.8A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affe...
CVE-2024-2826HIGH8.8A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects un...
CVE-2024-2825HIGH8.8A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown par...
CVE-2024-29499HIGH7.4Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
CVE-2024-29366HIGH8.8A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
CVE-2024-29184HIGH8FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been iden...
CVE-2024-2228HIGH8.8This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user...
CVE-2024-2227HIGH7.5This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulner...
CVE-2024-2725HIGH7.5Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/ins...
CVE-2024-2724HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. Th...
CVE-2024-2723HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exp...
CVE-2024-2722HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation...
CVE-2024-2449HIGH7.5A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who...
CVE-2024-2448HIGH8.8An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission s...
CVE-2024-29944HIGH8.4An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution...
CVE-2024-28559HIGH8.8SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPri...
CVE-2024-28824HIGH7.8Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b...
CVE-2024-1848HIGH7.8Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Typ...
CVE-2024-2812HIGH8.8A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the...
CVE-2024-25808HIGH8.3Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now