2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24278HIGH7.5An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive informa...
CVE-2024-1764HIGH7.6Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allow...
CVE-2024-25858HIGH8.4In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an ...
CVE-2024-25613HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-25612HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-25611HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-1356HIGH7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ...
CVE-2024-23296HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i...
CVE-2024-23225HIGH7.8A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i...
CVE-2024-22255HIGH7.1VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malic...
CVE-2024-22254HIGH8.2VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may ...
CVE-2024-27929HIGH7.1ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's Initi...
CVE-2024-27561HIGH8.1A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers...
CVE-2024-24098HIGH7.8Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
CVE-2024-27622HIGH7.2A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2...
CVE-2024-20838HIGH7.8Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitr...
CVE-2024-20835HIGH7.8Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local atta...
CVE-2024-22188HIGH7.2TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell co...
CVE-2024-1731HIGH8.8The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu...
CVE-2024-0825HIGH8.8The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-25269HIGH7.5libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a de...
CVE-2024-27718HIGH7.8SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s...
CVE-2024-25731HIGH7.5The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can ...
CVE-2024-25164HIGH7.5iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files...
CVE-2024-1936HIGH7.5The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email mess...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now