2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54236HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni Woo...
CVE-2024-54235HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiptimize Shiptim...
CVE-2024-54233HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in overclokk Advanced...
CVE-2024-54231HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni Woo...
CVE-2024-55889HIGH7.2phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record compon...
CVE-2024-22461HIGH8.8Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote att...
CVE-2024-52066HIGH7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routin...
CVE-2024-52065HIGH7.1Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-...
CVE-2024-52064HIGH7.1Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L...
CVE-2024-52063HIGH8.6Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L...
CVE-2024-52062HIGH7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L...
CVE-2024-52060HIGH7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routin...
CVE-2024-52059HIGH7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or ...
CVE-2024-52058HIGH7.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext ...
CVE-2024-10783HIGH8.1The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable...
CVE-2024-11839HIGH7.5Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra...
CVE-2024-11836HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue a...
CVE-2024-11835HIGH7.5Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61....
CVE-2024-21544HIGH8.6Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL ...
CVE-2024-21543HIGH7.1Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai...
CVE-2024-9508HIGH8.5Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose informat...
CVE-2024-12212HIGH8.5The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supp...
CVE-2024-55888HIGH7.1Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the p...
CVE-2024-55885HIGH7.5beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a has...
CVE-2024-55879HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now