LiveActive security incident?Get immediate response
CVE archive

2024 CVE Archive

Browse CVE records published in 2024 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 38426 matching CVEs · Page 8 of 769.

High · CVSS 7.5

CVE-2024-21490: This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

Published Feb 10, 2024 · Updated Jul 6, 2026

Medium · CVSS 4.8

CVE-2024-1248: Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Published Jul 4, 2026 · Updated Jul 6, 2026

High · CVSS 7.5

CVE-2024-6228: WANotifier < 2.6 - Subscriber+ LFI

The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.

Published Jul 6, 2026 · Updated Jul 6, 2026

High · CVSS 8.8

CVE-2024-35584: SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, funct...

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

Published Oct 15, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.1

CVE-2024-38891: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.

Published Aug 2, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.6

CVE-2024-38889: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

Published Aug 2, 2024 · Updated Jul 5, 2026

Medium · CVSS 6.8

CVE-2024-38888: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.

Published Aug 2, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.8

CVE-2024-38887: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.

Published Aug 2, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.8

CVE-2024-38886: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.

Published Aug 2, 2024 · Updated Jul 5, 2026

High · CVSS 7.5

CVE-2024-38885: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.

Published Aug 2, 2024 · Updated Jul 5, 2026

High · CVSS 7.8

CVE-2024-38884: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms

Published Aug 2, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.1

CVE-2024-38883: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

Published Aug 2, 2024 · Updated Jul 5, 2026

Critical · CVSS 9.8

CVE-2024-38882: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

Published Aug 2, 2024 · Updated Jul 5, 2026

High · CVSS 7.5

CVE-2024-38881: An issue in Horizon Business Services Inc.

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.

Published Aug 2, 2024 · Updated Jul 5, 2026

Medium · CVSS 6.5

CVE-2024-55488: A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitr...

A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.

Published Jan 22, 2025 · Updated Jul 5, 2026

Critical · CVSS 9.8

CVE-2024-42531: Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream...

Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.

Published Aug 23, 2024 · Updated Jul 5, 2026

Medium · CVSS 6.7

CVE-2024-42642: Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be trigg...

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

Published Sep 4, 2024 · Updated Jul 5, 2026

Medium · CVSS 6.5

CVE-2024-48705: Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-au...

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field

Published Sep 2, 2025 · Updated Jul 5, 2026