2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34352HIGH7.51Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many ...
CVE-2024-34351HIGH7.5Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery ...
CVE-2024-34350HIGH7.5Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsiste...
CVE-2024-34349MEDIUM4.8Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript c...
CVE-2024-34345HIGH8.1The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML Extern...
CVE-2024-34340CRITICAL9.1Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_pa...
CVE-2024-34338HIGH7.2Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest p...
CVE-2024-34310HIGH8.8Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id param...
CVE-2024-34308HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the funct...
CVE-2024-34245MEDIUM6.5An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by speci...
CVE-2024-34231HIGH7.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-34230MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-34226CRITICAL9.4SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0...
CVE-2024-34225MEDIUM6.1Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP...
CVE-2024-34224HIGH7.3Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using P...
CVE-2024-34223MEDIUM4.3Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow ...
CVE-2024-34222MEDIUM5.9Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVE-2024-34221HIGH8.8Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalat...
CVE-2024-34220HIGH7.5Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
CVE-2024-34219HIGH8.6TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allo...
CVE-2024-34218LOW3.8TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTP...
CVE-2024-34217HIGH7.7TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfil...
CVE-2024-34215HIGH7.3TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilte...
CVE-2024-34213CRITICAL9.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForw...
CVE-2024-34212HIGH7.3TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now