2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57407HIGH7.3An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar...
CVE-2024-54954HIGH8OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CVE-2024-48170MEDIUM5.4PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the...
CVE-2024-57950MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to...
CVE-2024-12243MEDIUM5.3A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libta...
CVE-2024-12133MEDIUM5.3A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements ...
CVE-2024-11831MEDIUM5.4A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not ...
CVE-2024-10334HIGH7.3A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  A...
CVE-2024-11621HIGH8.8Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to...
CVE-2024-8685MEDIUM4.3Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could...
CVE-2024-8684HIGH8.3OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability...
CVE-2024-57949MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_...
CVE-2024-13440HIGH8.2The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v...
CVE-2024-8377Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-6909Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5183Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-54176MEDIUM6.5IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 thro...
CVE-2024-13850MEDIUM4.8The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a...
CVE-2024-55630MEDIUM5.5Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into...
CVE-2024-57606HIGH7.5SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker ...
CVE-2024-57357HIGH8An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code...
CVE-2024-57279MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifical...
CVE-2024-57278MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vuln...
CVE-2024-55272HIGH7.5An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function...
CVE-2024-55215CRITICAL9.8An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now