2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28060HIGH7.3An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arb...
CVE-2024-5434MEDIUM6.9The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwo...
CVE-2024-5433MEDIUM5.3The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given exp...
CVE-2024-36110HIGH8.2ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTM...
CVE-2024-36109HIGH7.6CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected ve...
CVE-2024-36107MEDIUM5.3MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` an...
CVE-2024-33450HIGH7.5SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information
CVE-2024-24919HIGH8.6Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the inte...
CVE-2024-33402HIGH8.1A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System ...
CVE-2024-35563CRITICAL9.8CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param...
CVE-2024-35403LOW2.7TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function...
CVE-2024-35401MEDIUM5.9TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName para...
CVE-2024-35344CRITICAL9.9Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25...
CVE-2024-35343CRITICAL9.8Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP ...
CVE-2024-35342MEDIUM4.6Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volu...
CVE-2024-35341HIGH7.5Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET r...
CVE-2024-34854CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
CVE-2024-34852MEDIUM6.3F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point ...
CVE-2024-30165HIGH7.1Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute ...
CVE-2024-30164MEDIUM6.7Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wit...
CVE-2024-26024HIGH8.6SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.
CVE-2024-36472MEDIUM6.5In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network ...
CVE-2024-35621MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute ar...
CVE-2024-35324CRITICAL9.8Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
CVE-2024-33849MEDIUM6.5ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now