2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9033MEDIUM5.4A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ...
CVE-2024-9032HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec...
CVE-2024-9031MEDIUM5.4A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe...
CVE-2024-9030MEDIUM5.4A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod...
CVE-2024-9043CRITICAL9.8Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated...
CVE-2024-8853CRITICAL9.8The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to ...
CVE-2024-41721HIGH8.1An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti...
CVE-2024-9011CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an ...
CVE-2024-9009CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affe...
CVE-2024-47060MEDIUM6.5Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate...
CVE-2024-47000HIGH7.5Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre...
CVE-2024-46999MEDIUM6.5Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc...
CVE-2024-45810HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl...
CVE-2024-45809HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro...
CVE-2024-45808MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al...
CVE-2024-45807HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2...
CVE-2024-45806MEDIUM6.5Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl...
CVE-2024-9008CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affec...
CVE-2024-9007MEDIUM5.4A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of...
CVE-2024-9006HIGH8.8A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ...
CVE-2024-7207Rejected reason: Duplicate of CVE-2024-45806.
CVE-2024-46984CRITICAL9.8The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperabil...
CVE-2024-46983CRITICAL9.8sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses...
CVE-2024-45614MEDIUM5.4Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi...
CVE-2024-45410HIGH7.5Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now