2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-58276HIGH8.7Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that all...
CVE-2024-58275HIGH8.7Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save en...
CVE-2024-5401HIGH8.8Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager...
CVE-2024-45539HIGH7.5Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2...
CVE-2024-3884HIGH7.5A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDe...
CVE-2024-32643HIGH7.5Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the ...
CVE-2024-32642HIGH8.8Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl...
CVE-2024-45675HIGH7.8IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrato...
CVE-2024-53684HIGH8.8A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1...
CVE-2024-48894HIGH7.5A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A spe...
CVE-2024-48882HIGH7.5A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special...
CVE-2024-45370HIGH7.3An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System...
CVE-2024-39148HIGH8.1The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated ...
CVE-2024-32384HIGH7.4Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS sup...
CVE-2024-56089HIGH7.5An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake respons...
CVE-2024-14007HIGH8.7Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions ...
CVE-2024-14015HIGH7.1The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputtin...
CVE-2024-21923HIGH7.3Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially result...
CVE-2024-21922HIGH7.3A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resul...
CVE-2024-8527HIGH8.6Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may all...
CVE-2024-21635HIGH7.5Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh...
CVE-2024-9126HIGH7.5Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use...
CVE-2024-7017HIGH7.5Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potential...
CVE-2024-47866HIGH7.5Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argume...
CVE-2024-32011HIGH8.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now