2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30516HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio...
CVE-2024-30461HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ...
CVE-2024-23511MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH Th...
CVE-2024-55374MEDIUM5.3REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
CVE-2024-58338CRITICAL10Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ...
CVE-2024-58337HIGH8.7Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to...
CVE-2024-58336HIGH8.7Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s...
CVE-2024-58315HIGH7.8Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote...
CVE-2024-58247——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58246——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58245——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58244——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58243——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-58242——Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that w...
CVE-2024-27480CRITICAL9.8givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
CVE-2024-25183HIGH7.5givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
CVE-2024-25182CRITICAL9.8givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
CVE-2024-30855HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act...
CVE-2024-25181CRITICAL9.1A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR...
CVE-2024-44065CRITICAL9.8Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th...
CVE-2024-42718MEDIUM6.5A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft...
CVE-2024-29720MEDIUM5.5An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via...
CVE-2024-40317MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MyNET up to v26.08 allows attackers to execute arbitrary code in...
CVE-2024-39037MEDIUM6.5MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu paramete...
CVE-2024-35322MEDIUM6.1MyNET up to v26.08 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ficheiro param...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now