2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-2168HIGH7.2A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as crit...
CVE-2024-27889HIGH8.8Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista ...
CVE-2024-27199HIGH7.3In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
CVE-2024-27694HIGH7.4FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_cate...
CVE-2024-22452HIGH7.8Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low priv...
CVE-2024-0156HIGH7.8Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attack...
CVE-2024-0155HIGH7.8Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacke...
CVE-2024-26622HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control()...
CVE-2024-20034HIGH7.2In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalati...
CVE-2024-20029HIGH8.4In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local esc...
CVE-2024-20027HIGH7.9In da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of ...
CVE-2024-20005HIGH8.2In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of p...
CVE-2024-28088HIGH8.1LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path pa...
CVE-2024-28084HIGH7.5p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or pos...
CVE-2024-2149HIGH7.2A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affec...
CVE-2024-2148HIGH8.8A vulnerability classified as critical has been found in SourceCodester Online Mobile Management Store 1.0. This affects...
CVE-2024-27255HIGH7.5IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2...
CVE-2024-26469HIGH8.1Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaSho...
CVE-2024-25842HIGH7.5An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) mo...
CVE-2024-25839HIGH7.5An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before,...
CVE-2024-25844HIGH7.5An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26,...
CVE-2024-24307HIGH7.5Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.1...
CVE-2024-25016HIGH7.5IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a d...
CVE-2024-0795HIGH7.2If an attacked was given access to an instance with the admin or manager role there is no backend authentication that wo...
CVE-2024-25063HIGH7.5Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now