2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39398HIGH7.4Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Ex...
CVE-2024-39397CRITICAL9Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of Fil...
CVE-2024-6532MEDIUM6.4The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-38483MEDIUM6.7Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged at...
CVE-2024-4389HIGH8.8The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2024-41864HIGH7.8Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2024-41863MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2024-41862MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2024-41861MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2024-41860MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2024-41858HIGH7.8InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resu...
CVE-2024-7732CRITICAL9.8Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated re...
CVE-2024-7731CRITICAL9.8Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated re...
CVE-2024-7588MEDIUM6.4The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-7729HIGH7.5The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG...
CVE-2024-7728HIGH7.2The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi...
CVE-2024-38653HIGH7.5XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t...
CVE-2024-38652CRITICAL9.1Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to ac...
CVE-2024-37399HIGH7.5A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to c...
CVE-2024-37373HIGH7.2Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with...
CVE-2024-36136HIGH7.5An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the...
CVE-2024-20083CRITICAL9.8In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2024-20082CRITICAL9.8In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution ...
CVE-2024-7754HIGH7.5A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This i...
CVE-2024-7753HIGH7.5A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now