2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5746HIGH7.2A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the...
CVE-2024-37183HIGH7.5Plain text credentials and session ID can be captured with a network sniffer.
CVE-2024-36071MEDIUM6.3Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files u...
CVE-2024-31586MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerabili...
CVE-2024-30848MEDIUM6.1Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject ...
CVE-2024-29390HIGH7.3Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulner...
CVE-2024-6154MEDIUM6.7Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allow...
CVE-2024-6153HIGH7.8Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local...
CVE-2024-6147HIGH7.8Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers ...
CVE-2024-38093MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-38082MEDIUM4.7Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-37818HIGH8.6Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. ...
CVE-2024-37897MEDIUM5.4SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur...
CVE-2024-37699CRITICAL9.8An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.
CVE-2024-37674MEDIUM5.5Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field ...
CVE-2024-37352LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that...
CVE-2024-37351LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37350MEDIUM4.7There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13....
CVE-2024-37349LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37626HIGH8.8A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrar...
CVE-2024-37348LOW3.4There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att...
CVE-2024-37347LOW3.4There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secur...
CVE-2024-37346MEDIUM4.9There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13...
CVE-2024-37345MEDIUM5.4There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to ...
CVE-2024-37344LOW3.4There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now