2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27480CRITICAL9.8givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
CVE-2024-25183HIGH7.5givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
CVE-2024-25182CRITICAL9.8givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
CVE-2024-30855HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act...
CVE-2024-25181CRITICAL9.1A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR...
CVE-2024-44065CRITICAL9.8Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th...
CVE-2024-42718MEDIUM6.5A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft...
CVE-2024-29720MEDIUM5.5An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via...
CVE-2024-40317MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in...
CVE-2024-39037MEDIUM6.5MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete...
CVE-2024-35322MEDIUM6.1MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param...
CVE-2024-58335MEDIUM5OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not...
CVE-2024-57521CRITICAL10SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat...
CVE-2024-10398Rejected reason: This CVE id was assigned but later discarded.
CVE-2024-9684HIGH7.5FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me...
CVE-2024-24844HIGH7.5Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi...
CVE-2024-27708CRITICAL9.6Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t...
CVE-2024-25812MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.
CVE-2024-35321MEDIUM4.3MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame...
CVE-2024-25814MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.
CVE-2024-49587CRITICAL9.1Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha...
CVE-2024-58323MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch...
CVE-2024-58322MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping...
CVE-2024-58321MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v...
CVE-2024-58320MEDIUM6.9An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now