2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43035MEDIUM5.8Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V...
CVE-2024-57854CRITICAL9.1Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us...
CVE-2024-55027HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_...
CVE-2024-55026CRITICAL9.8An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers...
CVE-2024-55025MEDIUM6.5Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a...
CVE-2024-55024CRITICAL9.8An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v202310...
CVE-2024-55023MEDIUM5.3Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow...
CVE-2024-55022HIGH8.8Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerabi...
CVE-2024-55021HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
CVE-2024-55020CRITICAL9.8A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS ...
CVE-2024-55019HIGH7.5Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310...
CVE-2024-43766MEDIUM6.5In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th...
CVE-2024-31328HIGH8.8In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from ...
CVE-2024-50337MEDIUM5.3Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to...
CVE-2024-47886HIGH7.2Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a...
CVE-2024-10938MEDIUM6.5The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ...
CVE-2024-48928HIGH7.5Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec...
CVE-2024-56373HIGH8.4DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb...
CVE-2024-1524HIGH8.1When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ...
CVE-2024-58041CRITICAL9.1Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl...
CVE-2024-56208MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM...
CVE-2024-54222MEDIUM4.3Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr...
CVE-2024-52387MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2024-51915MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...
CVE-2024-50555MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now