2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25635HIGH8.8alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the gener...
CVE-2024-25982HIGH8.8The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-25978HIGH7.5Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25623HIGH7.7Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and...
CVE-2024-1580HIGH8.8An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to mem...
CVE-2024-25468HIGH7.5An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_t...
CVE-2024-25298HIGH7.2An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive inform...
CVE-2024-21492HIGH8.1All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to ...
CVE-2024-22727HIGH8.3Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability...
CVE-2024-20956HIGH7.3Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In...
CVE-2024-20953HIGH8.8Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that i...
CVE-2024-20931HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-20927HIGH8.6Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-20917HIGH7.5Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Log Manage...
CVE-2024-20909HIGH7.5Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a...
CVE-2024-25628HIGH7.6Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access t...
CVE-2024-25083HIGH7.8An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat...
CVE-2024-0023HIGH7.8In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds ch...
CVE-2024-0021HIGH7.8In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en...
CVE-2024-0018HIGH7.8In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overf...
CVE-2024-21915HIGH8.8 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, ...
CVE-2024-0015HIGH7.8In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to ...
CVE-2024-21775HIGH8.8Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in re...
CVE-2024-25466HIGH7.8Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local att...
CVE-2024-25415HIGH7.2A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to ex...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now