2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-0258HIGH8.6The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14....
CVE-2024-25729HIGH8.8Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (T...
CVE-2024-2267HIGH7.5A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0 and classified as problematic. This issue affects ...
CVE-2024-2265HIGH7.5A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affe...
CVE-2024-28115HIGH7.8FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficient...
CVE-2024-1986HIGH8.8The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ...
CVE-2024-0203HIGH8.8The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi...
CVE-2024-1773HIGH8.8The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2024-22752HIGH8.1Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use o...
CVE-2024-1442HIGH8.8 A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doin...
CVE-2024-27733HIGH7.7File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitr...
CVE-2024-1170HIGH8.2The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-1169HIGH7.5The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-1931HIGH7.5NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of se...
CVE-2024-1382HIGH8.8The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ...
CVE-2024-28215HIGH7.5nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which ...
CVE-2024-28094HIGH8.8Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the au...
CVE-2024-0815HIGH8.8Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0
CVE-2024-0817HIGH7.8Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
CVE-2024-26566HIGH8.2An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification co...
CVE-2024-24375HIGH7.5SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/adm...
CVE-2024-1299HIGH8.1A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to ...
CVE-2024-0199HIGH8An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to ...
CVE-2024-28110HIGH7.5Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15...
CVE-2024-27917HIGH7.5Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session C...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now