2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4948MEDIUM6.5Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-4947CRITICAL9.6Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside ...
CVE-2024-4913CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Examination System 1.0. This vulnerability affects ...
CVE-2024-4912CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Examination System 1.0. This affects an unknow...
CVE-2024-4911MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. A...
CVE-2024-27244HIGH7.8Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an aut...
CVE-2024-27243MEDIUM6.5Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via...
CVE-2024-4910MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical...
CVE-2024-4904MEDIUM6.3A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This i...
CVE-2024-34913MEDIUM5.4An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code vi...
CVE-2024-34909MEDIUM5.4An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploadin...
CVE-2024-34906MEDIUM5.4An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a cr...
CVE-2024-34025CRITICAL9.8CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could res...
CVE-2024-33625CRITICAL9.8CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacke...
CVE-2024-33615HIGH8.8A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel serve...
CVE-2024-32053CRITICAL9.8Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other servic...
CVE-2024-32047CRITICAL9.8Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might resul...
CVE-2024-32042HIGH7.5The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, ...
CVE-2024-31856HIGH8.8An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This coul...
CVE-2024-31410MEDIUM6.5The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. Thi...
CVE-2024-31409HIGH7.5Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtainin...
CVE-2024-4909MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critic...
CVE-2024-4908MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This ...
CVE-2024-4907MEDIUM6.5A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. ...
CVE-2024-4906HIGH7.5A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now