2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-24470HIGH8.8Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th...
CVE-2024-24161HIGH7.5MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not fil...
CVE-2024-23831HIGH7.5LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active sess...
CVE-2024-22107HIGH7.2An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/s...
CVE-2024-0269HIGH8.8ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary Dril...
CVE-2024-0253HIGH8.8ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
CVE-2024-1201HIGH7.8Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability co...
CVE-2024-0844HIGH7.2The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in ...
CVE-2024-22851HIGH7.5Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information ...
CVE-2024-24524HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code...
CVE-2024-21860HIGH8.8 in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use a...
CVE-2024-21851HIGH7.8 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.
CVE-2024-21845HIGH7.8 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.
CVE-2024-21780HIGH7.5Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted com...
CVE-2024-22320HIGH8.8IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the sys...
CVE-2024-22903HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-22900HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-22899HIGH8.8Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ...
CVE-2024-21399HIGH8.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-22016HIGH7.8In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada ...
CVE-2024-24756HIGH7.5Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/`...
CVE-2024-21852HIGH8.8In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration fi...
CVE-2024-0325HIGH7.8In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  
CVE-2024-1167HIGH7.5 When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.
CVE-2024-24557HIGH7.8Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now