2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28557CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-28556CRITICAL9.8SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr...
CVE-2024-24487MEDIUM6.8An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service vi...
CVE-2024-24486CRITICAL9.1An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the...
CVE-2024-24485HIGH7.5An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information...
CVE-2024-31219MEDIUM4.3Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site...
CVE-2024-2659HIGH7.2 A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat...
CVE-2024-28056CRITICAL9.8Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ...
CVE-2024-23594MEDIUM6.4 A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Win...
CVE-2024-23593MEDIUM6.7 A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 ope...
CVE-2024-23559MEDIUM6.1HCL DevOps Deploy / Launch is generating an obsolete HTTP header.
CVE-2024-22014HIGH8.8An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p...
CVE-2024-3797CRITICAL9.8A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab...
CVE-2024-31576Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-3786MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Devi...
CVE-2024-3785MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Devi...
CVE-2024-3784MEDIUM6.6Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 A...
CVE-2024-3783MEDIUM6.5The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low...
CVE-2024-3782HIGH8.8Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated H...
CVE-2024-3781CRITICAL9.1Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory...
CVE-2024-3780HIGH7.8A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerabi...
CVE-2024-24898MEDIUM6Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le...
CVE-2024-24891MEDIUM6Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le...
CVE-2024-3802Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-32129MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now