2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30202HIGH7.8In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6....
CVE-2024-29650CRITICAL9.8An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutIn...
CVE-2024-28183MEDIUM5.7ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o...
CVE-2024-25175MEDIUM6.1An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.
CVE-2024-2865CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu...
CVE-2024-28435MEDIUM5.4The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
CVE-2024-28434HIGH7.6The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil...
CVE-2024-28393CRITICAL9.8SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the Scal...
CVE-2024-28387HIGH7.5An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt compone...
CVE-2024-28386CRITICAL9.8An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getP...
CVE-2024-25002HIGH8.8Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access t...
CVE-2024-2864MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify ...
CVE-2024-25964HIGH7.5Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated at...
CVE-2024-30187MEDIUM5.3Anope before 2.0.15 does not prevent resetting the password of a suspended account.
CVE-2024-2863CRITICAL9.8This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
CVE-2024-2862CRITICAL9.8 This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect...
CVE-2024-29216MEDIUM6.1Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOC...
CVE-2024-24899HIGH7.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ao...
CVE-2024-24897HIGH8.1Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Co...
CVE-2024-24892HIGH8.1Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Managemen...
CVE-2024-24890HIGH7.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ga...
CVE-2024-29009MEDIUM6.1Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker...
CVE-2024-21865MEDIUM6.5HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at...
CVE-2024-21505HIGH7.5Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format a...
CVE-2024-1962HIGH8.8The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now