2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35219HIGH8.3OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat...
CVE-2024-32978MEDIUM6.6Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecu...
CVE-2024-0851CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy a...
CVE-2024-34477HIGH7.8configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafte...
CVE-2024-5409MEDIUM6.1RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker coul...
CVE-2024-5408MEDIUM6.1Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnera...
CVE-2024-5407CRITICAL9.8A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. ...
CVE-2024-3381Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5406MEDIUM6.3A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text an...
CVE-2024-5405MEDIUM6.3A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash...
CVE-2024-36383MEDIUM5.3An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the st...
CVE-2024-5035HIGH8.8The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ...
CVE-2024-5403HIGH7.2ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with adm...
CVE-2024-27314LOW2.4Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 1...
CVE-2024-26289CRITICAL9.8Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB:...
CVE-2024-5400HIGH8.8Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can expl...
CVE-2024-4535HIGH8.8The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow at...
CVE-2024-4534MEDIUM6.1The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing saniti...
CVE-2024-4533MEDIUM6.5The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a ...
CVE-2024-4532MEDIUM6.4The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-4531HIGH7.1The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-4530MEDIUM6.3The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-4529MEDIUM5The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-3939MEDIUM5.4The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-3933HIGH7.3In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScaveng...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now