2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23775HIGH7.5Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of...
CVE-2024-1069HIGH7.2The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio...
CVE-2024-1077HIGH8.8Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap...
CVE-2024-1060HIGH8.8Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap ...
CVE-2024-1059HIGH8.8Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially expl...
CVE-2024-23838HIGH7.5TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain con...
CVE-2024-23647HIGH8.8Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to c...
CVE-2024-21649HIGH8.8The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...
CVE-2024-1019HIGH8.6ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially...
CVE-2024-1033HIGH7.5A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is th...
CVE-2024-0676HIGH7.1Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a lo...
CVE-2024-0674HIGH7.8Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local ...
CVE-2024-1063HIGH7.5Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an...
CVE-2024-22523HIGH7.5Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive...
CVE-2024-21803HIGH7.8Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution ...
CVE-2024-21840HIGH7.1Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and...
CVE-2024-22938HIGH7.8Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri...
CVE-2024-23334HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and c...
CVE-2024-24140HIGH7.2Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
CVE-2024-24139HIGH7.2Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
CVE-2024-23940HIGH7.8Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and be...
CVE-2024-1017HIGH7.5A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown ...
CVE-2024-1016HIGH7.5A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affec...
CVE-2024-23828HIGH8.8Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execu...
CVE-2024-1011HIGH8.8A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now