2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54852CRITICAL9.8When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera...
CVE-2024-54851HIGH8.8Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
CVE-2024-51182MEDIUM6.1HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML c...
CVE-2024-48761HIGH8.8Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScr...
CVE-2024-23733HIGH7.5The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core...
CVE-2024-12705HIGH7.5Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i...
CVE-2024-11187HIGH7.5It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t...
CVE-2024-48852CRITICAL9.4Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di...
CVE-2024-48849CRITICAL9.4Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth...
CVE-2024-10001HIGH7.1A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod...
CVE-2024-57439MEDIUM4.9An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser...
CVE-2024-57438MEDIUM5.4Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe...
CVE-2024-57437MEDIUM6.5RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
CVE-2024-57436HIGH7.2RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring...
CVE-2024-54462HIGH7.1The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu...
CVE-2024-54461HIGH7.1The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc...
CVE-2024-41140MEDIUM6.5Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th...
CVE-2024-13561MEDIUM6.4The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov...
CVE-2024-57965CRITICAL9.8In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a po...
CVE-2024-7695HIGH8.7Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp...
CVE-2024-13696HIGH7.2The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored...
CVE-2024-12749HIGH7.1The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-57519HIGH7.5An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in ...
CVE-2024-56529HIGH7.1Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a sess...
CVE-2024-48310HIGH7.5AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now