2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25840HIGH7.5In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World ...
CVE-2024-24323HIGH7.2SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via ...
CVE-2024-1925HIGH8.1A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of t...
CVE-2024-27508HIGH7.5Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
CVE-2024-26142HIGH7.5Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept h...
CVE-2024-25398HIGH7.5In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service con...
CVE-2024-27507HIGH7.5libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
CVE-2024-25723HIGH8.8ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t...
CVE-2024-1920HIGH8.1A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects ...
CVE-2024-0819HIGH7.8 Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and ma...
CVE-2024-0551HIGH7.1Enable exports of the database and associated exported information of the system via the default user role. The attacked...
CVE-2024-0197HIGH7.8A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate the...
CVE-2024-0759HIGH7.5Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission l...
CVE-2024-25711HIGH7.5diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ....
CVE-2024-24100HIGH8.3Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
CVE-2024-24096HIGH7.8Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
CVE-2024-22917HIGH8.6SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute ar...
CVE-2024-27356HIGH7.5An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially ...
CVE-2024-22544HIGH8An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbi...
CVE-2024-27093HIGH7.5Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to re...
CVE-2024-26455HIGH7.5fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
CVE-2024-25768HIGH7.5OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
CVE-2024-27081HIGH8.8ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the...
CVE-2024-27454HIGH7.5orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.
CVE-2024-27359HIGH7.5Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when proce...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now