2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34067MEDIUM6.1Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg...
CVE-2024-34066HIGH8.4Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the ...
CVE-2024-31673CRITICAL9.8Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.
CVE-2024-27453HIGH8.6In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the...
CVE-2024-33793MEDIUM5.3netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test p...
CVE-2024-33792CRITICAL9.8netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert pag...
CVE-2024-33791MEDIUM4.6A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web sc...
CVE-2024-33789CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info...
CVE-2024-31636LOW3.9An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_re...
CVE-2024-30851MEDIUM6.5Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor...
CVE-2024-28519HIGH7.8A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privi...
CVE-2024-34449MEDIUM6.1Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigat...
CVE-2024-34447HIGH7.5An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78,...
CVE-2024-33398HIGH7.5There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allo...
CVE-2024-3480LOW2.8An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-r...
CVE-2024-3479LOW2.8 An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterpr...
CVE-2024-34446HIGH7.5Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a ...
CVE-2024-33844HIGH7.5The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attack...
CVE-2024-29417HIGH8.4Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges ...
CVE-2024-3109MEDIUM6.3 A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitatio...
CVE-2024-3108MEDIUM5.5 An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local a...
CVE-2024-1395MEDIUM6.7Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to...
CVE-2024-1067HIGH7.4Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2024-33787HIGH8.2Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerab...
CVE-2024-33786CRITICAL9.8An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now