2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-55948HIGH8.2Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re...
CVE-2024-43187HIGH7.5IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i...
CVE-2024-23690HIGH7.2The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac...
CVE-2024-40891HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le...
CVE-2024-40890HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL...
CVE-2024-10239HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin...
CVE-2024-10238HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo...
CVE-2024-10237HIGH7.2There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker ...
CVE-2024-13330HIGH7.1The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13329HIGH7.1The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-47770HIGH8Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin...
CVE-2024-35177HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin...
CVE-2024-57451HIGH7.5ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which ...
CVE-2024-56903HIGH8.1Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against ...
CVE-2024-56902HIGH7.5Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which ...
CVE-2024-56901HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha...
CVE-2024-56898HIGH8.8Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p...
CVE-2024-34897HIGH7.5Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
CVE-2024-34896HIGH7.5An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f...
CVE-2024-57968HIGH8.8Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones...
CVE-2024-57669HIGH7.5Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf...
CVE-2024-57452HIGH7.5ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows ...
CVE-2024-56921HIGH7.5An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF ...
CVE-2024-12859HIGH8.8The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-12511HIGH7.6With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now