2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33371 | MEDIUM | 6.1 | 0.5% | Apr 30, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typei... |
| CVE-2024-33332 | HIGH | 7.5 | 0.7% | Apr 30, 2024 | An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api... |
| CVE-2024-29384 | HIGH | 7.5 | 0.8% | Apr 30, 2024 | An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and... |
| CVE-2024-3411 | CRITICAL | 9.1 | 0.7% | Apr 30, 2024 | Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, all... |
| CVE-2024-34088 | HIGH | 7.5 | 0.7% | Apr 30, 2024 | In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a N... |
| CVE-2024-28269 | HIGH | 7.2 | 1.0% | Apr 30, 2024 | ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, le... |
| CVE-2024-26331 | HIGH | 7.5 | 49.3% | Apr 30, 2024 | ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind ... |
| CVE-2024-22546 | MEDIUM | 6.4 | 1.5% | Apr 30, 2024 | TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker wit... |
| CVE-2024-33832 | MEDIUM | 6.3 | 0.7% | Apr 30, 2024 | OneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /index.php?c=ap... |
| CVE-2024-33831 | HIGH | 7.4 | 0.5% | Apr 30, 2024 | A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows a... |
| CVE-2024-33103 | MEDIUM | 6.1 | 0.5% | Apr 30, 2024 | An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execut... |
| CVE-2024-33102 | MEDIUM | 5.4 | 0.4% | Apr 30, 2024 | A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attacker... |
| CVE-2024-33101 | MEDIUM | 6.1 | 0.4% | Apr 30, 2024 | A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers... |
| CVE-2024-23463 | HIGH | 8.1 | 0.4% | Apr 30, 2024 | Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repa... |
| CVE-2024-29320 | HIGH | 8.1 | 0.7% | Apr 30, 2024 | Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. |
| CVE-2024-4340 | HIGH | 7.5 | 3.2% | Apr 30, 2024 | Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError. |
| CVE-2024-33465 | HIGH | 7.1 | 0.4% | Apr 30, 2024 | Cross Site Scripting vulnerability in MajorDoMo before v.0662e5e allows an attacker to escalate privileges via the the t... |
| CVE-2024-33309 | HIGH | 7.5 | 0.8% | Apr 30, 2024 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sens... |
| CVE-2024-33308 | CRITICAL | 9.1 | 0.7% | Apr 30, 2024 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate pr... |
| CVE-2024-33275 | CRITICAL | 9.8 | 0.7% | Apr 30, 2024 | SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privilege... |
| CVE-2024-33274 | HIGH | 7.5 | 1.0% | Apr 30, 2024 | Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sens... |
| CVE-2024-33273 | CRITICAL | 9.8 | 0.6% | Apr 30, 2024 | SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID f... |
| CVE-2024-33270 | HIGH | 7.5 | 0.7% | Apr 30, 2024 | An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive ... |
| CVE-2024-33267 | CRITICAL | 9.8 | 0.5% | Apr 30, 2024 | SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the H... |
| CVE-2024-2877 | MEDIUM | 5.5 | 0.2% | Apr 30, 2024 | Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now