2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24350HIGH8.8File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary...
CVE-2024-24806HIGH7.3libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/g...
CVE-2024-23448HIGH7.5An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that index...
CVE-2024-24824HIGH8.8Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar...
CVE-2024-20290HIGH7.5A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a deni...
CVE-2024-20255HIGH7.1A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow...
CVE-2024-20254HIGH8.8Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ...
CVE-2024-20252HIGH8.8Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ...
CVE-2024-22012HIGH7.8there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ...
CVE-2024-25201HIGH7.5Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at sr...
CVE-2024-25200HIGH7.5Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse....
CVE-2024-1118HIGH8.8The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute ...
CVE-2024-24311HIGH7.5Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for Pr...
CVE-2024-24304HIGH7.5In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical info...
CVE-2024-24810HIGH7.8WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folde...
CVE-2024-22022HIGH8.8Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to a...
CVE-2024-22388HIGH7.8Certain configuration available in the communication channel for encoders could expose sensitive data when reader config...
CVE-2024-24680HIGH7.5An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma templa...
CVE-2024-24575HIGH7.5libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing...
CVE-2024-22520HIGH8.2An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of cra...
CVE-2024-22519HIGH8.2An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted da...
CVE-2024-22515HIGH8.8Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files v...
CVE-2024-22514HIGH8.8An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted ...
CVE-2024-22239HIGH7.8Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Ope...
CVE-2024-22237HIGH7.8Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Ope...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now