2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28418MEDIUM6.5Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVE-2024-28417MEDIUM6.3Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
CVE-2024-28383CRITICAL9.8Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 functio...
CVE-2024-1623HIGH7.8Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could al...
CVE-2024-2438Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-47851. Reason: This candidate is a ...
CVE-2024-2437Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-41728. Reason: This candidate is a ...
CVE-2024-28746HIGH8.1Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permiss...
CVE-2024-27986MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor...
CVE-2024-0313MEDIUM5.5A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organiza...
CVE-2024-0312MEDIUM5.5A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.
CVE-2024-0311MEDIUM5.5A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
CVE-2024-28391CRITICAL9.8SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote a...
CVE-2024-28390CRITICAL9.8An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escala...
CVE-2024-22398MEDIUM4.9An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securit...
CVE-2024-22397HIGH8.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows...
CVE-2024-22396MEDIUM5.3An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ...
CVE-2024-1884MEDIUM6.5This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an atta...
CVE-2024-1883MEDIUM6.1This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit...
CVE-2024-1882HIGH7.2This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for ...
CVE-2024-28388CRITICAL9.8SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote atta...
CVE-2024-25653MEDIUM4.3Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unli...
CVE-2024-25652HIGH8.4In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access...
CVE-2024-25651MEDIUM5.3User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attack...
CVE-2024-25649MEDIUM6.7In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machin...
CVE-2024-1654HIGH7.2This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now