2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27318HIGH7.5Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data fiel...
CVE-2024-23320HIGH8.8Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox...
CVE-2024-26150HIGH7.5`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building ...
CVE-2024-1821HIGH8.8A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects...
CVE-2024-26599HIGH7.8In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlat...
CVE-2024-26598HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI tr...
CVE-2024-26597HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_polic...
CVE-2024-1819HIGH7.2A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect...
CVE-2024-1818HIGH7.2A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this iss...
CVE-2024-26594HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If cli...
CVE-2024-25915HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: ...
CVE-2024-26593HIGH7.1In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions Acc...
CVE-2024-1776HIGH7.2The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par...
CVE-2024-22243HIGH8.1Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perf...
CVE-2024-1786HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 ...
CVE-2024-1683HIGH7.3 A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application fil...
CVE-2024-25756HIGH8A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote...
CVE-2024-25753HIGH8.8Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote a...
CVE-2024-25748HIGH8.8A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a re...
CVE-2024-25746HIGH8.8Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote a...
CVE-2024-1750HIGH8.1A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_u...
CVE-2024-1748HIGH7.5A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects ...
CVE-2024-26592HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() ...
CVE-2024-26589HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS...
CVE-2024-26588HIGH7.8In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now