2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25909HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media ...
CVE-2024-24714HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons...
CVE-2024-23839HIGH8.1Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-23837HIGH7.5LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP hea...
CVE-2024-23836HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-23835HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P...
CVE-2024-22873HIGH8.1Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subs...
CVE-2024-22371HIGH7.5Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo...
CVE-2024-22201HIGH7.5Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will...
CVE-2024-1889HIGH8.8Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability cou...
CVE-2024-1886HIGH8.8 This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
CVE-2024-1878HIGH8.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2024-1877HIGH8.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected b...
CVE-2024-1875HIGH8.8A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affec...
CVE-2024-1758HIGH8.1The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2024-1710HIGH8.8The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-1622HIGH7.5Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too q...
CVE-2024-0455HIGH7.5The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin...
CVE-2024-0439HIGH8.8As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience fo...
CVE-2024-0243HIGH8.1With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" ...
CVE-2024-21502HIGH7.5Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the cur...
CVE-2024-26192HIGH8.2Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-25469HIGH7.5SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive informat...
CVE-2024-24310HIGH8.8In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaS...
CVE-2024-24309HIGH7.5In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download pers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now