2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35099CRITICAL9.8TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the funct...
CVE-2024-35050HIGH8.8An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was del...
CVE-2024-35049CRITICAL9.1SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-...
CVE-2024-35048MEDIUM4.3An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
CVE-2024-34974HIGH8.2Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
CVE-2024-34946MEDIUM6.5Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame...
CVE-2024-34945CRITICAL9.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW paramet...
CVE-2024-34944HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 param...
CVE-2024-34943CRITICAL9.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame...
CVE-2024-34942HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 p...
CVE-2024-34921HIGH8.8TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
CVE-2024-34899MEDIUM5.4WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-34828MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin:...
CVE-2024-34827MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban Tra...
CVE-2024-34825MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: fro...
CVE-2024-34823MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects A...
CVE-2024-34818HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.1...
CVE-2024-34817MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elem...
CVE-2024-34816MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io...
CVE-2024-34814MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2...
CVE-2024-34812MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Build...
CVE-2024-34811MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ...
CVE-2024-34749MEDIUM6.1Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remot...
CVE-2024-34709MEDIUM5.4Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens functi...
CVE-2024-34708MEDIUM4.9Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any coll...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now