2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2644CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected ...
CVE-2024-2642HIGH7.3A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vul...
CVE-2024-2641MEDIUM5.3A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unk...
CVE-2024-28715HIGH8.8Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via t...
CVE-2024-28389CRITICAL9.8SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileg...
CVE-2024-28283MEDIUM6.7There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v....
CVE-2024-28092HIGH7.2UBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct s...
CVE-2024-24336HIGH8.1A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endp...
CVE-2024-2169HIGH7.5Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use malic...
CVE-2024-28595CRITICAL9.8SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the ad...
CVE-2024-28394CRITICAL9.8An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via...
CVE-2024-29027CRITICAL9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2024-28303CRITICAL9.8Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter...
CVE-2024-2545Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1730. Reason: This candidate is a d...
CVE-2024-2442HIGH7.5 Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attac...
CVE-2024-2307MEDIUM6.1A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositori...
CVE-2024-29094MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Easy ...
CVE-2024-29093MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes –...
CVE-2024-29092MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permali...
CVE-2024-29091HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dnesscarkey WP Arm...
CVE-2024-29089MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins ...
CVE-2024-27998HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of ...
CVE-2024-27997MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi...
CVE-2024-27996MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team ...
CVE-2024-21677HIGH8.8This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Tr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now