2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53588HIGH7.8A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL fil...
CVE-2024-50664HIGH7.8gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.
CVE-2024-55928HIGH7.5Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta...
CVE-2024-55927HIGH7.5A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn...
CVE-2024-55925HIGH7.5In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se...
CVE-2024-52331HIGH7.7ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea...
CVE-2024-52329HIGH7.4ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack...
CVE-2024-11147HIGH7.6ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An at...
CVE-2024-13593HIGH8.8The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2....
CVE-2024-12957HIGH8.4A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ...
CVE-2024-57722HIGH7.5lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.
CVE-2024-56924HIGH7.3A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to...
CVE-2024-11166HIGH7.1For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a grou...
CVE-2024-55957HIGH7.8In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 ...
CVE-2024-31903HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on th...
CVE-2024-24429HIGH8.6A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of ...
CVE-2024-34235HIGH8.6Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the...
CVE-2024-24430HIGH7.5A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv...
CVE-2024-13499HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13496HIGH7.5The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2024-13495HIGH7.3The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress...
CVE-2024-13361HIGH8.8The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che...
CVE-2024-11218HIGH8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a...
CVE-2024-49749HIGH8.8In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot...
CVE-2024-49745HIGH7.8In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now