2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22780MEDIUM6.1Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a cra...
CVE-2024-30965HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php...
CVE-2024-30621CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
CVE-2024-30620CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
CVE-2024-30946MEDIUM5.5DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.
CVE-2024-2389CRITICAL9.8In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified...
CVE-2024-29514HIGH8.8File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload...
CVE-2024-29949HIGH7.2There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administr...
CVE-2024-29948LOW3.8There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulner...
CVE-2024-29947LOW2.7There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a paramet...
CVE-2024-2745LOW3.3Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sens...
CVE-2024-1946MEDIUM6.4The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versio...
CVE-2024-1807MEDIUM6.5The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2024-1732MEDIUM5.3The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of d...
CVE-2024-2931MEDIUM4.3The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-31005HIGH8.1An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_Mdhd...
CVE-2024-31004CRITICAL9.8An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_Stsd...
CVE-2024-31003HIGH8.8Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4...
CVE-2024-31002CRITICAL9.8Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4...
CVE-2024-20799MEDIUM5.4Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-1300MEDIUM5.4A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. W...
CVE-2024-2925MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-2839MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_pos...
CVE-2024-29276CRITICAL9.8An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess m...
CVE-2024-29086MEDIUM5.5in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now