2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25126HIGH7.5Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser t...
CVE-2024-23910HIGH8.8Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote...
CVE-2024-25869HIGH8.8An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacke...
CVE-2024-25866HIGH8.8A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute...
CVE-2024-22983HIGH8.1SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate...
CVE-2024-25859HIGH7.1A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover u...
CVE-2024-24148HIGH7.5A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service...
CVE-2024-27948HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through ...
CVE-2024-26342HIGH7.5A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via ...
CVE-2024-1847HIGH7.8Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Typ...
CVE-2024-21749HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all:...
CVE-2024-24702HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Rest...
CVE-2024-27515HIGH7.2Osclass 5.1.2 is vulnerable to SQL Injection.
CVE-2024-25902HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware...
CVE-2024-24868HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro...
CVE-2024-21886HIGH7.8A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an appli...
CVE-2024-21885HIGH7.8A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated arr...
CVE-2024-1514HIGH7.5The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter ...
CVE-2024-26298HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26297HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26296HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26295HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26294HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-0763HIGH8.1Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path t...
CVE-2024-24027HIGH7.2SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now