2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48091HIGH7.8Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. Thi...
CVE-2024-35106MEDIUM4.6NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability all...
CVE-2024-10383MEDIUM6.1An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions pri...
CVE-2024-13841MEDIUM4.3The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to In...
CVE-2024-13492MEDIUM6.1The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13352HIGH7.1The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-57609HIGH8.6An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute...
CVE-2024-57392HIGH7.5Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can caus...
CVE-2024-56889HIGH7.5Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth...
CVE-2024-55241HIGH8.8An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m...
CVE-2024-54909HIGH8.1A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/...
CVE-2024-53586MEDIUM5.3An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra...
CVE-2024-48589MEDIUM6.3Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code vi...
CVE-2024-25883MEDIUM5.3The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.
CVE-2024-56467LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-54171HIGH7.1IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat...
CVE-2024-57673MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Lin...
CVE-2024-57672MEDIUM5.5An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topolo...
CVE-2024-57426HIGH7.3NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali...
CVE-2024-52892MEDIUM6.1IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2024-47258HIGH8.12N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif...
CVE-2024-47256MEDIUM6Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to rea...
CVE-2024-13417MEDIUM4.6Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it ...
CVE-2024-57668HIGH8.8In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
CVE-2024-57523MEDIUM4.5Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attacke...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now