2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41922HIGH7.5A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia...
CVE-2024-41163HIGH7.5A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted...
CVE-2024-39755HIGH7.8A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr...
CVE-2024-36474HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc...
CVE-2024-25590HIGH7.5An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for...
CVE-2024-9460CRITICAL9.8A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unk...
CVE-2024-9100MEDIUM6.5Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera...
CVE-2024-5803HIGH7.5The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a...
CVE-2024-47618MEDIUM5.4Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the...
CVE-2024-47617MEDIUM6.1Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code ...
CVE-2024-47614HIGH7.5async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ...
CVE-2024-47554MEDIUM4.3Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c...
CVE-2024-9313HIGH8.8Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b...
CVE-2024-47561CRITICAL9.2Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. ...
CVE-2024-42504MEDIUM4.3A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery...
CVE-2024-8159MEDIUM6.4Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of t...
CVE-2024-8352HIGH7.5The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory...
CVE-2024-47136HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2024-47135HIGH7.8Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming S...
CVE-2024-47134HIGH7.8Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)...
CVE-2024-47616MEDIUM6.8Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all ...
CVE-2024-45519CRITICAL9.8The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,...
CVE-2024-28888HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A special...
CVE-2024-24117CRITICAL9.8Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to g...
CVE-2024-8733HIGH8A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now