2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43364HIGH8.2Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when...
CVE-2024-43363HIGH7.2Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious h...
CVE-2024-43362MEDIUM5.4Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized wh...
CVE-2024-47976MEDIUM6.7Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to ...
CVE-2024-47972MEDIUM4Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the p...
CVE-2024-47971MEDIUM6.5Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.
CVE-2024-47079MEDIUM6.4Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht...
CVE-2024-45293HIGH7.5PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for pre...
CVE-2024-45292MEDIUM5.4PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` ...
CVE-2024-31449HIGH8.8Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua...
CVE-2024-31228MEDIUM6.5Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service b...
CVE-2024-31227MEDIUM4.4Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat...
CVE-2024-47975HIGH7Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access t...
CVE-2024-47559HIGH8.8Authenticated RCE via Path Traversal
CVE-2024-47558HIGH8.8Authenticated RCE via Path Traversal
CVE-2024-47557CRITICAL9.8Pre-Auth RCE via Path Traversal
CVE-2024-47556CRITICAL9.8Pre-Auth RCE via Path Traversal
CVE-2024-45894MEDIUM4.9BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
CVE-2024-44068HIGH8.1An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 9...
CVE-2024-47555HIGH8.3Missing Authentication - User & System Configuration
CVE-2024-46076CRITICAL9.8RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabl...
CVE-2024-44674MEDIUM5.7D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained thr...
CVE-2024-42831MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex...
CVE-2024-46300MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-27458HIGH8.8A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escala...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now