2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27192HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Confi...
CVE-2024-25921HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Concerted Action A...
CVE-2024-2490HIGH8.8A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the functi...
CVE-2024-2450HIGH8.8Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctl...
CVE-2024-2489HIGH8.8A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand...
CVE-2024-2488HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function form...
CVE-2024-2487HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the fu...
CVE-2024-2486HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQ...
CVE-2024-28353HIGH8.8There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker ...
CVE-2024-2485HIGH8.8A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function f...
CVE-2024-27756HIGH8.8GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.
CVE-2024-1795HIGH8.8The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'na...
CVE-2024-2480HIGH8.8A vulnerability classified as critical was found in MHA Sistemas arMHAzena 9.6.0.0. This vulnerability affects unknown c...
CVE-2024-26540HIGH7.8A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_lo...
CVE-2024-1713HIGH7.2A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as t...
CVE-2024-0860HIGH7.5 The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow ...
CVE-2024-28425HIGH7.5greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/...
CVE-2024-28424HIGH8.8zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cl...
CVE-2024-27301HIGH7.3Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability i...
CVE-2024-27266HIGH8.2IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML ...
CVE-2024-22346HIGH7.8Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqua...
CVE-2024-28181HIGH8.1 turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoo...
CVE-2024-1623HIGH7.8Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could al...
CVE-2024-28746HIGH8.1Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permiss...
CVE-2024-22397HIGH8.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now