2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37779HIGH8.8WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t...
CVE-2024-39843MEDIUM6.7A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-39842HIGH7.2A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-39342MEDIUM6.6Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use...
CVE-2024-39341MEDIUM5.9Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and...
CVE-2024-0005HIGH8.8A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel...
CVE-2024-0004HIGH7.2A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to...
CVE-2024-0003HIGH7.2A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an ...
CVE-2024-0002CRITICAL9.8A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to th...
CVE-2024-0001CRITICAL9.8A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active ...
CVE-2024-9014MEDIUM6.5pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ...
CVE-2024-40442HIGH7.2An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-40441MEDIUM6.6An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-47069MEDIUM6.1Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set...
CVE-2024-47068MEDIUM6.1Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber...
CVE-2024-47066HIGH8.8Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger...
CVE-2024-46997CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote com...
CVE-2024-46985HIGH7.5DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in...
CVE-2024-41228HIGH7.6A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es...
CVE-2024-34331CRITICAL9.8A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privil...
CVE-2024-23972MEDIUM6.8Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-23934HIGH8.8Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-23933MEDIUM6.8Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-23922MEDIUM6.8Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-46241MEDIUM5.9PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now