2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-23733HIGH7.5The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core...
CVE-2024-12705HIGH7.5Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i...
CVE-2024-11187HIGH7.5It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t...
CVE-2024-10001HIGH7.1A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod...
CVE-2024-57436HIGH7.2RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring...
CVE-2024-54462HIGH7.1The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu...
CVE-2024-54461HIGH7.1The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc...
CVE-2024-7695HIGH8.7Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp...
CVE-2024-13696HIGH7.2The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored...
CVE-2024-12749HIGH7.1The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-57519HIGH7.5An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in ...
CVE-2024-56529HIGH7.1Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a sess...
CVE-2024-48310HIGH7.5AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers ...
CVE-2024-57376HIGH8.8Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C...
CVE-2024-55968HIGH8.8An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handli...
CVE-2024-40677HIGH8.4In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections...
CVE-2024-40676HIGH7.7In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an ...
CVE-2024-40675HIGH7.5In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead ...
CVE-2024-40672HIGH8.4In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis...
CVE-2024-40670HIGH8.4In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2024-40669HIGH8.4In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2024-40651HIGH8.4In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ...
CVE-2024-40649HIGH8.4In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ...
CVE-2024-34748HIGH8.4In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi...
CVE-2024-34733HIGH8.4In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now