2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54270HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-51646HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saoshyant1994 Saos...
CVE-2024-49677HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Boots...
CVE-2024-11912HIGH7.5The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id...
CVE-2024-11614HIGH7.4An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an un...
CVE-2024-54457HIGH7.2Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE102...
CVE-2024-53688HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmwa...
CVE-2024-47397HIGH7.5Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 an...
CVE-2024-39703HIGH8.8In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted...
CVE-2024-56174HIGH8.1In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-4464HIGH7.5Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-...
CVE-2024-21548HIGH7.5Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input s...
CVE-2024-21547HIGH7.7Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation i...
CVE-2024-12432HIGH8.1The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati...
CVE-2024-12259HIGH8.8The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i...
CVE-2024-12025HIGH7.5The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js...
CVE-2024-47480HIGH7.8Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne...
CVE-2024-9779HIGH7.5A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-m...
CVE-2024-51175HIGH7.5An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.
CVE-2024-49194HIGH7.3Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI inject...
CVE-2024-51479HIGH7.5Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is ...
CVE-2024-49819HIGH7.5IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti...
CVE-2024-12671HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12670HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul...
CVE-2024-12669HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now