2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-1882HIGH7.2This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for ...
CVE-2024-25652HIGH8.4In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access...
CVE-2024-1654HIGH7.2This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker...
CVE-2024-25228HIGH8.8Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerify...
CVE-2024-28251HIGH7.3Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's da...
CVE-2024-27102HIGH8.5Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions...
CVE-2024-24105HIGH7.8SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary co...
CVE-2024-22167HIGH7.9A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrar...
CVE-2024-0801HIGH7.5A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
CVE-2024-0800HIGH8.8A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca....
CVE-2024-2432HIGH7A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local...
CVE-2024-28195HIGH8.8your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the ...
CVE-2024-20327HIGH7.4A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series ...
CVE-2024-20320HIGH7.8A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Conve...
CVE-2024-20318HIGH7.4A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attac...
CVE-2024-0162HIGH8.8Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner...
CVE-2024-2194HIGH7.2The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all ...
CVE-2024-2106HIGH7.5The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Informatio...
CVE-2024-2006HIGH8.8The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v...
CVE-2024-28673HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.
CVE-2024-28671HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.
CVE-2024-26630HIGH7.1In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache w...
CVE-2024-24549HIGH7.5Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing a...
CVE-2024-1951HIGH7.5The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Inj...
CVE-2024-1950HIGH8.8The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now