2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-12200HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12199HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12198HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12197HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12194HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A...
CVE-2024-12193HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12192HIGH7.8A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability....
CVE-2024-12191HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability...
CVE-2024-12179HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul...
CVE-2024-12178HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A...
CVE-2024-11422HIGH7.8A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability...
CVE-2024-10476HIGH8Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be ab...
CVE-2024-36832HIGH7.5A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via...
CVE-2024-8326HIGH8.8The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2024-12293HIGH8.8The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2024-11999HIGH8.8CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic...
CVE-2024-9624HIGH7.6The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2024-38499HIGH8.8CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul...
CVE-2024-56017HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects...
CVE-2024-52949HIGH7.5iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th...
CVE-2024-37775HIGH7.5Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh...
CVE-2024-37774HIGH8A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv...
CVE-2024-55104HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin...
CVE-2024-55103HIGH7.2Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile....
CVE-2024-12666HIGH8.8A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now