2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2426HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ...
CVE-2024-2425HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ...
CVE-2024-29440Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-29179MEDIUM4.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with ...
CVE-2024-29041MEDIUM6.1Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta ...
CVE-2024-29025MEDIUM5.3Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2024-28246MEDIUM5.4KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically tha...
CVE-2024-28245MEDIUM6.1KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-28244MEDIUM6.5KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-28243MEDIUM6.5KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-29666CRITICAL9.8Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a re...
CVE-2024-29515HIGH8.8File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload...
CVE-2024-28850HIGH8.1WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative u...
CVE-2024-28108MEDIUM6.1phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficie...
CVE-2024-28107HIGH8.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection ...
CVE-2024-28106MEDIUM5.4phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating t...
CVE-2024-28105HIGH7.2phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category imag...
CVE-2024-27300MEDIUM5.4phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field...
CVE-2024-27299HIGH8.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection v...
CVE-2024-30205HIGH7.1In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
CVE-2024-30204LOW2.8In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
CVE-2024-30203MEDIUM5.5In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
CVE-2024-30202HIGH7.8In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6....
CVE-2024-29650CRITICAL9.8An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutIn...
CVE-2024-28183MEDIUM5.7ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now