2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-2805HIGH8.8A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issu...
CVE-2024-29031HIGH7.5Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur...
CVE-2024-28171HIGH8.1 It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specif...
CVE-2024-28040HIGH8.8 SQL injection vulnerability exists in GetDIAE_astListParameters.
CVE-2024-25567HIGH8.8 Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If ...
CVE-2024-23975HIGH8.8 SQL injection vulnerability exists in GetDIAE_slogListParameters.
CVE-2024-23494HIGH8.8 SQL injection vulnerability exists in GetDIAE_unListParameters.
CVE-2024-28891HIGH8.8 SQL injection vulnerability exists in the script Handler_CFG.ashx.
CVE-2024-28521HIGH7.8SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute ar...
CVE-2024-28119HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ...
CVE-2024-28118HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ...
CVE-2024-28117HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible function...
CVE-2024-28116HIGH8.8Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-...
CVE-2024-28029HIGH8.8Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authoriza...
CVE-2024-27921HIGH8.8Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identif...
CVE-2024-25937HIGH8.8 SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.
CVE-2024-24272HIGH7.1An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive inf...
CVE-2024-2764HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formS...
CVE-2024-2763HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is ...
CVE-2024-29180HIGH7.5Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not valida...
CVE-2024-27964HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: ...
CVE-2024-27190HIGH8.8Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a thro...
CVE-2024-2465HIGH7.1Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafte...
CVE-2024-2463HIGH8Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX app...
CVE-2024-27994HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooC...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now