2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-22720MEDIUM4.8Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
CVE-2024-23641HIGH7.5SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/h...
CVE-2024-22229MEDIUM4.3 Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated atta...
CVE-2024-22725MEDIUM6.1Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability w...
CVE-2024-22651CRITICAL9.8There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmwa...
CVE-2024-22141HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue af...
CVE-2024-22154HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects Sal...
CVE-2024-22309CRITICAL9.8Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from...
CVE-2024-22308MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affec...
CVE-2024-22301HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i...
CVE-2024-22294HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This...
CVE-2024-22284CRITICAL9.8Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/...
CVE-2024-22152HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is...
CVE-2024-22135HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.T...
CVE-2024-22134MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affe...
CVE-2024-0854MEDIUM5.4URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manag...
CVE-2024-0665MEDIUM6.1The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all...
CVE-2024-22372MEDIUM6.8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat...
CVE-2024-22366MEDIUM6.8Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug...
CVE-2024-22380MEDIUM5.5Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development ...
CVE-2024-21796MEDIUM5.5Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creat...
CVE-2024-21765MEDIUM5.5Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 a...
CVE-2024-23638MEDIUM6.5Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable ...
CVE-2024-23633MEDIUM6.1Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w...
CVE-2024-23453MEDIUM5.5Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retri...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now