2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-58283HIGH8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali...
CVE-2024-58282HIGH7.2Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali...
CVE-2024-58281HIGH8.8Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP...
CVE-2024-58280HIGH8.8CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten...
CVE-2024-58279HIGH8.8appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo...
CVE-2024-2104HIGH8.8Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read a...
CVE-2024-56840HIGH7.5A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56839HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56838HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56837HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56836HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56835HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-58278HIGH8.5perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to exec...
CVE-2024-58277HIGH8.7R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the sys...
CVE-2024-58276HIGH8.7Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that all...
CVE-2024-58275HIGH8.7Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save en...
CVE-2024-5401HIGH8.8Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager...
CVE-2024-45539HIGH7.5Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2...
CVE-2024-3884HIGH7.5A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDe...
CVE-2024-32643HIGH7.5Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the ...
CVE-2024-32642HIGH8.8Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl...
CVE-2024-45675HIGH7.8IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrato...
CVE-2024-53684HIGH8.8A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1...
CVE-2024-48894HIGH7.5A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A spe...
CVE-2024-48882HIGH7.5A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now