2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33423 | HIGH | 7.4 | 0.6% | May 1, 2024 | Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary we... |
| CVE-2024-33307 | MEDIUM | 5.4 | 0.4% | May 1, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in... |
| CVE-2024-33306 | HIGH | 7.4 | 0.7% | May 1, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter i... |
| CVE-2024-25676 | MEDIUM | 4.7 | 0.3% | May 1, 2024 | An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanit... |
| CVE-2024-24403 | — | — | — | May 1, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-30176. Reason: This record is a reservation duplicate ... |
| CVE-2024-33431 | MEDIUM | 6.5 | 0.9% | May 1, 2024 | An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via ... |
| CVE-2024-33430 | HIGH | 8.8 | 1.4% | May 1, 2024 | An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-33429 | HIGH | 7.1 | 1.1% | May 1, 2024 | Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary cod... |
| CVE-2024-33428 | HIGH | 8.8 | 1.2% | May 1, 2024 | Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-33424 | MEDIUM | 6.1 | 0.4% | May 1, 2024 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary ... |
| CVE-2024-33393 | MEDIUM | 6.2 | 0.2% | May 1, 2024 | An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c... |
| CVE-2024-33304 | MEDIUM | 6.1 | 0.4% | May 1, 2024 | SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users. |
| CVE-2024-33300 | HIGH | 7.3 | 0.6% | May 1, 2024 | Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows ... |
| CVE-2024-33292 | HIGH | 8.2 | 0.5% | May 1, 2024 | SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the i... |
| CVE-2024-29011 | HIGH | 7.5 | 0.9% | May 1, 2024 | Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects G... |
| CVE-2024-26504 | HIGH | 8.8 | 0.5% | May 1, 2024 | An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst pa... |
| CVE-2024-25458 | HIGH | 7.5 | 0.6% | May 1, 2024 | An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0... |
| CVE-2024-25355 | HIGH | 7.5 | 0.6% | May 1, 2024 | s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component. |
| CVE-2024-24313 | HIGH | 7.5 | 0.6% | May 1, 2024 | An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Mode... |
| CVE-2024-24312 | HIGH | 7.5 | 0.5% | May 1, 2024 | SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive infor... |
| CVE-2024-22830 | MEDIUM | 5.3 | 0.2% | May 1, 2024 | Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control wh... |
| CVE-2024-33442 | MEDIUM | 4.3 | 0.6% | May 1, 2024 | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component. |
| CVE-2024-33078 | CRITICAL | 9.8 | 1.1% | May 1, 2024 | Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to r... |
| CVE-2024-32213 | MEDIUM | 5.3 | 0.9% | May 1, 2024 | The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, ... |
| CVE-2024-32212 | HIGH | 8.1 | 0.7% | May 1, 2024 | SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute ar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now