2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-35141HIGH7.8IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe...
CVE-2024-56319HIGH7.5In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userla...
CVE-2024-56318HIGH7.5In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer d...
CVE-2024-56317HIGH7.5In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries ...
CVE-2024-56116HIGH8.8A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator ...
CVE-2024-55506HIGH8.8An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex...
CVE-2024-53580HIGH7.5iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-41159HIGH7.1A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage ...
CVE-2024-55505HIGH8.8An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie...
CVE-2024-12695HIGH8.8Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code i...
CVE-2024-12694HIGH8.8Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit ...
CVE-2024-12693HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar...
CVE-2024-12692HIGH8.8Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-12686HIGH7.2A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacke...
CVE-2024-53271HIGH7.1Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle...
CVE-2024-53270HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to...
CVE-2024-53269HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then t...
CVE-2024-49363HIGH7.4Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in gith...
CVE-2024-36694HIGH7.2OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
CVE-2024-12741HIGH8.4A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Succ...
CVE-2024-56057HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56055HIGH8.8Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM...
CVE-2024-56054HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56053HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w...
CVE-2024-56052HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now