2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58335MEDIUM5OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not...
CVE-2024-57521CRITICAL10SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat...
CVE-2024-10398——Rejected reason: This CVE id was assigned but later discarded.
CVE-2024-9684HIGH7.5FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me...
CVE-2024-24844HIGH7.5Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi...
CVE-2024-27708CRITICAL9.6Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t...
CVE-2024-25812MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.
CVE-2024-35321MEDIUM4.3MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parame...
CVE-2024-25814MEDIUM6.1MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.
CVE-2024-49587CRITICAL9.1Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha...
CVE-2024-58323MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Ch...
CVE-2024-58322MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping...
CVE-2024-58321MEDIUM5.4A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form v...
CVE-2024-58320MEDIUM6.9An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration inte...
CVE-2024-58319MEDIUM6.1A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the...
CVE-2024-58318MEDIUM6.1A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the ri...
CVE-2024-58317MEDIUM6.9A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when sett...
CVE-2024-46062HIGH7.8Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t...
CVE-2024-46060HIGH7.8Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th...
CVE-2024-29371HIGH7.5In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry...
CVE-2024-29370MEDIUM5.3In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) c...
CVE-2024-44599HIGH8.3FNT Command 13.4.0 is vulnerable to Directory Traversal.
CVE-2024-44598HIGH8.8FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2024-58316HIGH8.7Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows...
CVE-2024-58314HIGH8.8Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now