2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21870MEDIUM4.9A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Pla...
CVE-2024-0394HIGH7.8Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated atta...
CVE-2024-3258HIGH7.2A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical....
CVE-2024-3257HIGH7.2A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected...
CVE-2024-3256HIGH7.2A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Aff...
CVE-2024-30572HIGH8Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
CVE-2024-30571HIGH7.5An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive inform...
CVE-2024-30570MEDIUM5.3An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without...
CVE-2024-30569HIGH7.5An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information wi...
CVE-2024-30568CRITICAL9.8Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-27254MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to...
CVE-2024-25096CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i...
CVE-2024-25046MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by ...
CVE-2024-25030MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log f...
CVE-2024-24707CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Inject...
CVE-2024-22360MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a speci...
CVE-2024-3255HIGH7.2A vulnerability, which was classified as critical, was found in SourceCodester Internship Portal Management System 1.0. ...
CVE-2024-3254HIGH7.2A vulnerability, which was classified as critical, has been found in SourceCodester Internship Portal Management System ...
CVE-2024-31390CRITICAL9.9: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.T...
CVE-2024-31380CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. ...
CVE-2024-29477HIGH8.8Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjace...
CVE-2024-28782MEDIUM6.5IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores u...
CVE-2024-27972CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.Thi...
CVE-2024-27951HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows U...
CVE-2024-27191HIGH8.5Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now