2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-26283HIGH7.8An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external...
CVE-2024-26282HIGH7.1Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. Th...
CVE-2024-25851HIGH8Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in...
CVE-2024-1563HIGH8.1An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external...
CVE-2024-26352HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places...
CVE-2024-26350HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_con...
CVE-2024-23094HIGH8.8Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_med...
CVE-2024-25021HIGH8.4IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execut...
CVE-2024-1104HIGH7.5An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all us...
CVE-2024-0220HIGH8.1B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the...
CVE-2024-27283HIGH7.2A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload po...
CVE-2024-26483HIGH8.8An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbit...
CVE-2024-26482HIGH7.1An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes ...
CVE-2024-23137HIGH7.8A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uni...
CVE-2024-23136HIGH7.8A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference a...
CVE-2024-23135HIGH7.8A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after...
CVE-2024-23134HIGH7.8A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerabil...
CVE-2024-23133HIGH7.8A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corrup...
CVE-2024-23132HIGH7.8A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory co...
CVE-2024-23131HIGH7.8A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll t...
CVE-2024-23130HIGH7.8A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a m...
CVE-2024-23129HIGH7.8A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can le...
CVE-2024-23128HIGH7.8A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can l...
CVE-2024-23127HIGH7.8A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk app...
CVE-2024-23126HIGH7.8A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-bas...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now