2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-53256HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code ...
CVE-2024-45387HIGH8.8An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with...
CVE-2024-12903HIGH7.8Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl...
CVE-2024-12902HIGH8.4ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows...
CVE-2024-54082HIGH7.2home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio...
CVE-2024-45721HIGH7.2home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n...
CVE-2024-56375HIGH7.5An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from...
CVE-2024-56311HIGH8.8REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Reques...
CVE-2024-56310HIGH8.8REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery...
CVE-2024-12891HIGH8.8A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an ...
CVE-2024-12890HIGH8.8A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue a...
CVE-2024-12771HIGH8.8The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12721HIGH7.2The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-12066HIGH8.8The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ...
CVE-2024-11977HIGH7.3The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-56335HIGH7.5vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve...
CVE-2024-56334HIGH7.8systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ...
CVE-2024-56329HIGH8.9Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo...
CVE-2024-12867HIGH8.8Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent...
CVE-2024-37758HIGH8.8Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker...
CVE-2024-12677HIGH8.5Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
CVE-2024-55470HIGH7.5Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ...
CVE-2024-10385HIGH8.6Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p...
CVE-2024-56356HIGH7.1In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-56351HIGH8.8In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now