2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29185CRITICAL9FreeScout is a self-hosted help desk and shared mailbox. Versions prior to 1.8.128 are vulnerable to OS Command Injectio...
CVE-2024-29184HIGH8FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been iden...
CVE-2024-29042MEDIUM5.3Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to ver...
CVE-2024-28861CRITICAL9.8Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version...
CVE-2024-2821MEDIUM4.3A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unkn...
CVE-2024-2820MEDIUM4.3A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functio...
CVE-2024-2228HIGH8.8This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user...
CVE-2024-2227HIGH7.5This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulner...
CVE-2024-29865MEDIUM5.4Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2024-28593MEDIUM5.4The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTM...
CVE-2024-2728MEDIUM5.5Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept t...
CVE-2024-2727MEDIUM6.1HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify ...
CVE-2024-2726MEDIUM6.1Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and...
CVE-2024-2725HIGH7.5Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/ins...
CVE-2024-2724HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. Th...
CVE-2024-2723HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exp...
CVE-2024-2722HIGH7.5SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation...
CVE-2024-2449HIGH7.5A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who...
CVE-2024-2448HIGH8.8An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission s...
CVE-2024-29944HIGH8.4An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution...
CVE-2024-29943CRITICAL9.8An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec...
CVE-2024-28560MEDIUM5.4SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the delete...
CVE-2024-28559HIGH8.8SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPri...
CVE-2024-25168MEDIUM6.3SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope pa...
CVE-2024-28824HIGH7.8Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now