2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33423HIGH7.4Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary we...
CVE-2024-33307MEDIUM5.4SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in...
CVE-2024-33306HIGH7.4SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter i...
CVE-2024-25676MEDIUM4.7An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanit...
CVE-2024-24403Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-30176. Reason: This record is a reservation duplicate ...
CVE-2024-33431MEDIUM6.5An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via ...
CVE-2024-33430HIGH8.8An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ...
CVE-2024-33429HIGH7.1Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary cod...
CVE-2024-33428HIGH8.8Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ...
CVE-2024-33424MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary ...
CVE-2024-33393MEDIUM6.2An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c...
CVE-2024-33304MEDIUM6.1SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.
CVE-2024-33300HIGH7.3Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows ...
CVE-2024-33292HIGH8.2SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the i...
CVE-2024-29011HIGH7.5Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects G...
CVE-2024-26504HIGH8.8An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst pa...
CVE-2024-25458HIGH7.5An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0...
CVE-2024-25355HIGH7.5s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.
CVE-2024-24313HIGH7.5An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Mode...
CVE-2024-24312HIGH7.5SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive infor...
CVE-2024-22830MEDIUM5.3Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control wh...
CVE-2024-33442MEDIUM4.3An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.
CVE-2024-33078CRITICAL9.8Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to r...
CVE-2024-32213MEDIUM5.3The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, ...
CVE-2024-32212HIGH8.1SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute ar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now