2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-50617HIGH7.5Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to...
CVE-2024-50620HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon...
CVE-2024-26480HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p...
CVE-2024-26477HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par...
CVE-2024-36324HIGH8.8Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia...
CVE-2024-36320HIGH7Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to ...
CVE-2024-56808HIGH7.8A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network...
CVE-2024-36355HIGH7Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec...
CVE-2024-5386HIGH8.8In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user ...
CVE-2024-54263HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-4027HIGH7.5A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an...
CVE-2024-11976HIGH7.3The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ...
CVE-2024-44238HIGH7.8The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1...
CVE-2024-48077HIGH7.5NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of reque...
CVE-2024-58340HIGH7.5LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the...
CVE-2024-58339HIGH7.5LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vuln...
CVE-2024-14021HIGH7.8LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i...
CVE-2024-30547HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea...
CVE-2024-53735HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We...
CVE-2024-30516HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio...
CVE-2024-30461HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ...
CVE-2024-58337HIGH8.7Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to...
CVE-2024-58336HIGH8.7Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s...
CVE-2024-58315HIGH7.8Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote...
CVE-2024-25183HIGH7.5givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now