2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0649CRITICAL9.8A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download...
CVE-2024-0648CRITICAL9.8A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown ...
CVE-2024-22414MEDIUM5.4flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user...
CVE-2024-22410HIGH7.8Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loa...
CVE-2024-0647MEDIUM6.1A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an un...
CVE-2024-22715HIGH8.8Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.ph...
CVE-2024-22714MEDIUM6.1Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
CVE-2024-20287HIGH7.2A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) wit...
CVE-2024-20277HIGH8A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installa...
CVE-2024-20272CRITICAL9.8A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2024-20270MEDIUM5.4A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadW...
CVE-2024-20251MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2024-0646HIGH7.8An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user ...
CVE-2024-0641MEDIUM5.5A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC su...
CVE-2024-0639MEDIUM5.5A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux...
CVE-2024-0396HIGH7.1 In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023....
CVE-2024-0645HIGH7.8Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code v...
CVE-2024-0643CRITICAL9.8Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerabi...
CVE-2024-0642CRITICAL9.8Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remo...
CVE-2024-0405MEDIUM6.5The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticat...
CVE-2024-22409HIGH8.8DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group ...
CVE-2024-22408HIGH8.1Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application d...
CVE-2024-22407MEDIUM6.5Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently ...
CVE-2024-22406CRITICAL9.8Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enabl...
CVE-2024-22916CRITICAL9.8In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now