2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36413MEDIUM5.4SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-36412CRITICAL9.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-36411HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-32167CRITICAL9.1Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend...
CVE-2024-27792MEDIUM5.5This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An a...
CVE-2024-23299HIGH8.6The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ven...
CVE-2024-22279HIGH7.5Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrad...
CVE-2024-36410HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-36409HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-31612MEDIUM6.5Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerabili...
CVE-2024-5597CRITICAL9.8Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution.
CVE-2024-5102HIGH7A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privile...
CVE-2024-3850MEDIUM5.4Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL...
CVE-2024-36408HIGH8.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-36407MEDIUM6.5SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-35754MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer ...
CVE-2024-35749MEDIUM5.3Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authe...
CVE-2024-35747MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in wpdevart Contact Form Builder, Contact Widget...
CVE-2024-35746CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection...
CVE-2024-35745HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Gabriel Somoza / Joseph ...
CVE-2024-35744MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upun...
CVE-2024-35743MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Siteclean SC filechecker...
CVE-2024-35728MEDIUM5.3Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Them...
CVE-2024-31611CRITICAL9.1SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
CVE-2024-37051HIGH7.5GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now