2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34352 | HIGH | 7.5 | 1.3% | May 14, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many ... |
| CVE-2024-34351 | HIGH | 7.5 | 5.5% | May 14, 2024 | Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery ... |
| CVE-2024-34350 | HIGH | 7.5 | 1.2% | May 14, 2024 | Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsiste... |
| CVE-2024-34349 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript c... |
| CVE-2024-34345 | HIGH | 8.1 | 0.9% | May 14, 2024 | The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML Extern... |
| CVE-2024-34340 | CRITICAL | 9.1 | 1.1% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_pa... |
| CVE-2024-34338 | HIGH | 7.2 | 2.8% | May 14, 2024 | Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest p... |
| CVE-2024-34310 | HIGH | 8.8 | 0.9% | May 14, 2024 | Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id param... |
| CVE-2024-34308 | HIGH | 8.8 | 0.6% | May 14, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the funct... |
| CVE-2024-34245 | MEDIUM | 6.5 | 0.8% | May 14, 2024 | An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by speci... |
| CVE-2024-34231 | HIGH | 7.1 | 0.5% | May 14, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-34230 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-34226 | CRITICAL | 9.4 | 0.8% | May 14, 2024 | SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0... |
| CVE-2024-34225 | MEDIUM | 6.1 | 0.6% | May 14, 2024 | Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP... |
| CVE-2024-34224 | HIGH | 7.3 | 0.9% | May 14, 2024 | Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using P... |
| CVE-2024-34223 | MEDIUM | 4.3 | 0.5% | May 14, 2024 | Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow ... |
| CVE-2024-34222 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter. |
| CVE-2024-34221 | HIGH | 8.8 | 0.8% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalat... |
| CVE-2024-34220 | HIGH | 7.5 | 0.8% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter. |
| CVE-2024-34219 | HIGH | 8.6 | 20.8% | May 14, 2024 | TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allo... |
| CVE-2024-34218 | LOW | 3.8 | 17.6% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTP... |
| CVE-2024-34217 | HIGH | 7.7 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfil... |
| CVE-2024-34215 | HIGH | 7.3 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilte... |
| CVE-2024-34213 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForw... |
| CVE-2024-34212 | HIGH | 7.3 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now