2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12829HIGH8.8Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2024-54663HIGH7.5An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl...
CVE-2024-12700HIGH8.8There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up...
CVE-2024-12729HIGH8.8A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho...
CVE-2024-12672HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-12175HIGH7.8Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat...
CVE-2024-11364HIGH7.3Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow ...
CVE-2024-11157HIGH7.3A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the...
CVE-2024-12111HIGH8In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac...
CVE-2024-56200HIGH8.6Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr...
CVE-2024-55196HIGH7.5Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl...
CVE-2024-38819HIGH7.5Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa...
CVE-2024-12790HIGH8.2A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnera...
CVE-2024-9154HIGH8.6A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. T...
CVE-2024-55082HIGH7.5A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attac...
CVE-2024-54790HIGH7.5A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remo...
CVE-2024-25131HIGH8.8A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-priv...
CVE-2024-12786HIGH8.5A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i...
CVE-2024-12785HIGH8.8A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by t...
CVE-2024-12782HIGH7.3A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an...
CVE-2024-12569HIGH7.8Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allow...
CVE-2024-4230HIGH7.8External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and ...
CVE-2024-4229HIGH7.8Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecros...
CVE-2024-11740HIGH7.3The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and ...
CVE-2024-51532HIGH7.1Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now