2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50452MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl...
CVE-2024-43228MEDIUM5.3Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th...
CVE-2024-34438MEDIUM5.3Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a...
CVE-2024-43178HIGH7.5IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2024-55270HIGH8.8phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata...
CVE-2024-55271LOW3.5A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issu...
CVE-2024-31118MEDIUM6.5Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure...
CVE-2024-34157——Rejected reason: reserved but not needed
CVE-2024-34154——Rejected reason: reserved but not needed
CVE-2024-21961MEDIUM6Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces...
CVE-2024-36319MEDIUM6.3Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr...
CVE-2024-50619HIGH8.8Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es...
CVE-2024-50617HIGH7.5Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to...
CVE-2024-50620HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon...
CVE-2024-50618MEDIUM4.3A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 all...
CVE-2024-26480HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p...
CVE-2024-26479MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command...
CVE-2024-26478MEDIUM5.3An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us...
CVE-2024-26477HIGH7.5An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par...
CVE-2024-36324HIGH8.8Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia...
CVE-2024-36320HIGH7Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to ...
CVE-2024-36316MEDIUM5.5The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially ...
CVE-2024-56808HIGH7.8A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network...
CVE-2024-56807MEDIUM5.5An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local netwo...
CVE-2024-36355HIGH7Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify exec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now