2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-22567HIGH8.8File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/...
CVE-2024-24267HIGH7.5gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_b...
CVE-2024-24266HIGH7.5gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src...
CVE-2024-24265HIGH7.5gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_int...
CVE-2024-24263HIGH7.5Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_lin...
CVE-2024-24262HIGH7.5media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function a...
CVE-2024-24260HIGH7.5media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function...
CVE-2024-24259HIGH7.5freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry functi...
CVE-2024-24258HIGH7.5freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
CVE-2024-24469HIGH8.8Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th...
CVE-2024-24468HIGH8.8Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th...
CVE-2024-24768HIGH7.51Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the p...
CVE-2024-24762HIGH7.5`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular E...
CVE-2024-22667HIGH7.8Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the err...
CVE-2024-20015HIGH7.8In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalati...
CVE-2024-20009HIGH8.8In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote e...
CVE-2024-20007HIGH7.5In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of...
CVE-2024-20004HIGH7.5In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ...
CVE-2024-20003HIGH7.5In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ...
CVE-2024-25062HIGH7.5An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD ...
CVE-2024-1064HIGH7.5A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticate...
CVE-2024-0909HIGH7.5The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and...
CVE-2024-1199HIGH7.5A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected ...
CVE-2024-1189HIGH7.5A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown ...
CVE-2024-24760HIGH7.3mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now