2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48589MEDIUM6.3Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code vi...
CVE-2024-25883MEDIUM5.3The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.
CVE-2024-56467LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-54171HIGH7.1IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat...
CVE-2024-57673MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Lin...
CVE-2024-57672MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topolo...
CVE-2024-57426HIGH7.3NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali...
CVE-2024-52892MEDIUM6.1IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2024-47258HIGH8.12N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif...
CVE-2024-47256MEDIUM6Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to rea...
CVE-2024-13417MEDIUM4.6Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it ...
CVE-2024-57668HIGH8.8In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
CVE-2024-57523MEDIUM4.5Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attacke...
CVE-2024-13416MEDIUM4.3Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system...
CVE-2024-57610HIGH7.5A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco...
CVE-2024-36558HIGH7.5Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ...
CVE-2024-36557MEDIUM6.6The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Fo...
CVE-2024-36556CRITICAL9.1Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3...
CVE-2024-36555CRITICAL9.8Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an...
CVE-2024-36554CRITICAL9.8Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36...
CVE-2024-36553HIGH8.1Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
CVE-2024-57599MEDIUM4.8Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a cra...
CVE-2024-57430CRITICAL9.8An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers...
CVE-2024-57429MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2....
CVE-2024-57428CRITICAL9.3A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now