2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58301CRITICAL9.3Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri...
CVE-2024-58300HIGH8.7Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac...
CVE-2024-58298CRITICAL9.2Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate...
CVE-2024-58297MEDIUM5.4PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att...
CVE-2024-58296MEDIUM5.3CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow...
CVE-2024-58295HIGH8.6ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma...
CVE-2024-58294HIGH8.8FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va...
CVE-2024-58293HIGH8.6Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec...
CVE-2024-58292MEDIUM5.3XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2024-58291MEDIUM5.3Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma...
CVE-2024-58290CRITICAL9.3Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers...
CVE-2024-58289MEDIUM5.4Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2024-58288HIGH8.7Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service...
CVE-2024-58287HIGH8.8reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all...
CVE-2024-58286CRITICAL9.3dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through...
CVE-2024-42197MEDIUM5.5HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
CVE-2024-8273HIGH8.8Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor...
CVE-2024-40593MEDIUM4.4A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, ...
CVE-2024-58285MEDIUM5.4Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scr...
CVE-2024-58284HIGH7.2PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj...
CVE-2024-58283HIGH8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali...
CVE-2024-58282HIGH7.2Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali...
CVE-2024-58281HIGH8.8Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP...
CVE-2024-58280HIGH8.8CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten...
CVE-2024-58279HIGH8.8appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now