2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34751MEDIUM4.4Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affe...
CVE-2024-34273MEDIUM5.9njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.
CVE-2024-35039LOW3.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.
CVE-2024-34958MEDIUM6.5idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=...
CVE-2024-34957MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mu...
CVE-2024-34905HIGH7.5FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerabil...
CVE-2024-34582MEDIUM6.1Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Passw...
CVE-2024-31142HIGH7.5Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intende...
CVE-2024-20389HIGH7.8A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated...
CVE-2024-20326HIGH7.8A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated...
CVE-2024-4999CRITICAL9.4A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote a...
CVE-2024-4760MEDIUM6.3A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, ...
CVE-2024-4993MEDIUM5.4Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote ...
CVE-2024-4992CRITICAL9.8Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This ...
CVE-2024-4991CRITICAL9.8Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. ...
CVE-2024-4826CRITICAL9.8SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacke...
CVE-2024-4580MEDIUM5.4The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-30314HIGH7.8Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an ...
CVE-2024-30292HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30291HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30290HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could res...
CVE-2024-30289HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...
CVE-2024-30288HIGH7.8Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou...
CVE-2024-30287MEDIUM5.5Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that co...
CVE-2024-30286MEDIUM5.5Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now