2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36599MEDIUM6.1A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2024-36598HIGH8.1An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a cra...
CVE-2024-36597HIGH8.8Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
CVE-2024-24320HIGH8.8Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sen...
CVE-2024-5659MEDIUM6.5Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result...
CVE-2024-37369HIGH8.8A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edi...
CVE-2024-5934Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-37887LOW3.5Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be re...
CVE-2024-37886MEDIUM4.7user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into acceptin...
CVE-2024-37885HIGH7.8The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection i...
CVE-2024-37884MEDIUM5.4Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versi...
CVE-2024-37883MEDIUM4.3Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2024-37882HIGH8.1Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshar...
CVE-2024-37645HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter...
CVE-2024-37643HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter...
CVE-2024-37642CRITICAL9.1TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_p...
CVE-2024-37641HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSc...
CVE-2024-37317MEDIUM4.6The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder c...
CVE-2024-37316MEDIUM4.6Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachmen...
CVE-2024-37315MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore ...
CVE-2024-33373MEDIUM6.3An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single...
CVE-2024-37644HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, w...
CVE-2024-37368HIGH7.5A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u...
CVE-2024-37367HIGH7.5A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows...
CVE-2024-37314LOW3.5Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommende...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now