2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45798CRITICAL9.9arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th...
CVE-2024-45612MEDIUM5.3Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic...
CVE-2024-45537MEDIUM6.5Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali...
CVE-2024-45384MEDIUM5.3Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ...
CVE-2024-43460HIGH8.8Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke...
CVE-2024-38183CRITICAL9.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-8945HIGH8.8A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulner...
CVE-2024-8944CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affec...
CVE-2024-8796MEDIUM5.3Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120...
CVE-2024-45804Rejected reason: This CVE is a duplicate of another CVE.
CVE-2024-45682CRITICAL9.8There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operatin...
CVE-2024-42503HIGH7.2Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio...
CVE-2024-42502HIGH7.2Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t...
CVE-2024-42501HIGH7.2An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability all...
CVE-2024-38813CRITICAL9.8The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Serve...
CVE-2024-38812CRITICAL9.8The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious acto...
CVE-2024-38380MEDIUM5.4This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser...
CVE-2024-8939MEDIUM6.2A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll...
CVE-2024-8768HIGH7.5A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, res...
CVE-2024-7788HIGH7.8Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows ...
CVE-2024-47049HIGH8.2The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URL...
CVE-2024-47047HIGH7.5An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of ...
CVE-2024-38860MEDIUM6.1Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li...
CVE-2024-22303HIGH8.8Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:...
CVE-2024-21743HIGH8.8Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now