2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-14031HIGH8.1Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-14030HIGH8.1Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library. Se...
CVE-2024-11604HIGH7.3Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Exte...
CVE-2024-14028MEDIUM6.5Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects...
CVE-2024-58341HIGH8.2OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate databas...
CVE-2024-51348HIGH8.8A stack-based buffer overflow vulnerability in the P2P API service in BS Producten Petcam with firmware 33.1.0.0818 allo...
CVE-2024-51347HIGH7.2A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handli...
CVE-2024-51346HIGH7.7An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptograph...
CVE-2024-46879MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in...
CVE-2024-46878MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea...
CVE-2024-51226MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51225MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man...
CVE-2024-51224MEDIUM4.8Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor...
CVE-2024-51223MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-51222MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-13785MEDIUM5.6The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc...
CVE-2024-44722CRITICAL9.8SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
CVE-2024-32537HIGH7.1Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This...
CVE-2024-31119MEDIUM5.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl...
CVE-2024-42210MEDIUM5.4A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cros...
CVE-2024-14026HIGH7.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai...
CVE-2024-14025MEDIUM6.7An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ...
CVE-2024-14024MEDIUM6.7An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n...
CVE-2024-14027MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat...
CVE-2024-35644MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now