2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12746HIGH8.6A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege...
CVE-2024-12745HIGH8.6A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc...
CVE-2024-12744HIGH8.6A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc...
CVE-2024-53162HIGH7.1In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na...
CVE-2024-53156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h...
CVE-2024-53155HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i...
CVE-2024-53150HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when findi...
CVE-2024-53147HIGH7.1In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entrie...
CVE-2024-12881HIGH8.8The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary ...
CVE-2024-12594HIGH8.8The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora...
CVE-2024-47515HIGH8.1A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di...
CVE-2024-12582HIGH7.1A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri...
CVE-2024-53961HIGH8.1ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di...
CVE-2024-56363HIGH7.8APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo...
CVE-2024-56326HIGH7.8Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca...
CVE-2024-56201HIGH8.8Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo...
CVE-2024-55947HIGH8.8Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser...
CVE-2024-53256HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code ...
CVE-2024-45387HIGH8.8An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with...
CVE-2024-12903HIGH7.8Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl...
CVE-2024-12902HIGH8.4ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows...
CVE-2024-54082HIGH7.2home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio...
CVE-2024-45721HIGH7.2home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n...
CVE-2024-56375HIGH7.5An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from...
CVE-2024-56311HIGH8.8REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Reques...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now