2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23125HIGH7.8A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-b...
CVE-2024-23124HIGH7.8A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Wr...
CVE-2024-23123HIGH7.8A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an...
CVE-2024-23122HIGH7.8A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write ...
CVE-2024-23121HIGH7.8A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Writ...
CVE-2024-25423HIGH7An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 fil...
CVE-2024-25251HIGH8.8code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
CVE-2024-23120HIGH7.8A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD...
CVE-2024-1451HIGH8.7An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload ...
CVE-2024-0446HIGH7.8A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk A...
CVE-2024-0410HIGH7.7An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16...
CVE-2024-26147HIGH7.5Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerab...
CVE-2024-23654HIGH7.2discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c393...
CVE-2024-25461HIGH7.5Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain s...
CVE-2024-24479HIGH7.5A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str....
CVE-2024-24476HIGH7.5A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resol...
CVE-2024-22473HIGH7.5TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. T...
CVE-2024-25892HIGH8.1ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.
CVE-2024-25891HIGH7.5ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET paramete...
CVE-2024-1705HIGH8.1A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCr...
CVE-2024-1704HIGH8.1A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the...
CVE-2024-26130HIGH7.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in vers...
CVE-2024-24478HIGH7.5An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_b...
CVE-2024-23346HIGH7.8Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulner...
CVE-2024-20325HIGH7.1A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now