2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28823MEDIUM6.1Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.ht...
CVE-2024-28816HIGH7.1Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.
CVE-2024-2184CRITICAL9.8Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printe...
CVE-2024-2365MEDIUM4.2A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is ...
CVE-2024-2364MEDIUM4.6A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown functi...
CVE-2024-2363MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. ...
CVE-2024-2314LOW2.5If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attack...
CVE-2024-2313LOW2.8If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged a...
CVE-2024-2355LOW3.7A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. Affected by thi...
CVE-2024-2354MEDIUM6.5A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of...
CVE-2024-2353HIGH8.8A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue af...
CVE-2024-28757HIGH7.5libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via...
CVE-2024-2352CRITICAL9.8A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is ...
CVE-2024-2351CRITICAL9.8A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an u...
CVE-2024-27698Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-2333HIGH7.2A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unkn...
CVE-2024-2332HIGH7.2A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issu...
CVE-2024-2331CRITICAL9.8A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulne...
CVE-2024-1870MEDIUM4.3The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-2330CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This...
CVE-2024-2329CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by t...
CVE-2024-25501HIGH8.8An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to t...
CVE-2024-28089MEDIUM5.2Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to th...
CVE-2024-1767MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up ...
CVE-2024-1320MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now