2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58319MEDIUM6.1A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the...
CVE-2024-58318MEDIUM6.1A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri...
CVE-2024-58317MEDIUM6.9A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett...
CVE-2024-46062HIGH7.8Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t...
CVE-2024-46060HIGH7.8Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th...
CVE-2024-29371HIGH7.5In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry...
CVE-2024-29370MEDIUM5.3In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c...
CVE-2024-44599HIGH8.3FNT Command 13.4.0 is vulnerable to Directory Traversal.
CVE-2024-44598HIGH8.8FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2024-58316HIGH8.7Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows...
CVE-2024-58314HIGH8.8Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi...
CVE-2024-58311CRITICAL9.8Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access...
CVE-2024-58305HIGH8.8WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu...
CVE-2024-58299CRITICAL9.8PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu...
CVE-2024-14010CRITICAL9.8Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a...
CVE-2024-58313HIGH7.2xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr...
CVE-2024-58312HIGH7.5xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ...
CVE-2024-58310HIGH8.7APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se...
CVE-2024-58309CRITICAL9.8xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa...
CVE-2024-58308CRITICAL9.8Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio...
CVE-2024-58307HIGH8.8CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent...
CVE-2024-58306HIGH8.7minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending...
CVE-2024-58304HIGH7.5SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allo...
CVE-2024-58303HIGH8.6FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject...
CVE-2024-58302MEDIUM6.9FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now