2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13416MEDIUM4.3Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system...
CVE-2024-57610HIGH7.5A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco...
CVE-2024-36558HIGH7.5Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ...
CVE-2024-36557MEDIUM6.6The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Fo...
CVE-2024-36556CRITICAL9.1Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3...
CVE-2024-36555CRITICAL9.8Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an...
CVE-2024-36554CRITICAL9.8Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36...
CVE-2024-36553HIGH8.1Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
CVE-2024-57599MEDIUM4.8Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a cra...
CVE-2024-57430CRITICAL9.8An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers...
CVE-2024-57429MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2....
CVE-2024-57428CRITICAL9.3A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp...
CVE-2024-57427MEDIUM6.1PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improper...
CVE-2024-43779MEDIUM6.5An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. ...
CVE-2024-39272HIGH8.2A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22....
CVE-2024-39033HIGH7.5In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows u...
CVE-2024-13614MEDIUM5.3Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Ligh...
CVE-2024-43811——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2024-24911HIGH7.5In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, ...
CVE-2024-57962HIGH7.5Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this v...
CVE-2024-57961CRITICAL9.8Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause fe...
CVE-2024-57960HIGH7.5Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerabi...
CVE-2024-57959CRITICAL9.8Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause...
CVE-2024-57958CRITICAL9.1Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may caus...
CVE-2024-57957HIGH7.5Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now