2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-25728HIGH7.5ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configur...
CVE-2024-25419HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_men...
CVE-2024-25418HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_men...
CVE-2024-25417HIGH8.8flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_transl...
CVE-2024-22313HIGH7.8IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, ...
CVE-2024-22361HIGH7.5IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weak...
CVE-2024-0594HIGH8.8The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injectio...
CVE-2024-21490HIGH7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular express...
CVE-2024-24828HIGH7.8pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t...
CVE-2024-23327HIGH7.5Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, t...
CVE-2024-23325HIGH7.5Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i...
CVE-2024-23324HIGH7.5Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections...
CVE-2024-23322HIGH7.5Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same int...
CVE-2024-1404HIGH7.5A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unkno...
CVE-2024-25450HIGH8.8imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
CVE-2024-25448HIGH8.8An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow ...
CVE-2024-25447HIGH8.8An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer ove...
CVE-2024-25446HIGH7.8An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer over...
CVE-2024-25445HIGH7.8Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
CVE-2024-25443HIGH7.8An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-...
CVE-2024-25442HIGH7.8An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap bu...
CVE-2024-25318HIGH8.8Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
CVE-2024-25310HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5....
CVE-2024-25313HIGH8.8Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a...
CVE-2024-25312HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now