2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-58311CRITICAL9.8Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access...
CVE-2024-58305HIGH8.8WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu...
CVE-2024-58299CRITICAL9.8PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu...
CVE-2024-14010CRITICAL9.8Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a...
CVE-2024-58313HIGH7.2xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr...
CVE-2024-58312HIGH7.5xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ...
CVE-2024-58310HIGH8.7APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se...
CVE-2024-58309CRITICAL9.8xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa...
CVE-2024-58308CRITICAL9.8Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio...
CVE-2024-58307HIGH8.8CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent...
CVE-2024-58306HIGH8.7minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending...
CVE-2024-58304MEDIUM6.1SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that...
CVE-2024-58303HIGH8.6FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject...
CVE-2024-58302MEDIUM6.9FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrar...
CVE-2024-58301CRITICAL9.3Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri...
CVE-2024-58300HIGH8.7Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac...
CVE-2024-58298CRITICAL9.2Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate...
CVE-2024-58297MEDIUM5.4PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows att...
CVE-2024-58296MEDIUM5.3CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allow...
CVE-2024-58295HIGH8.6ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma...
CVE-2024-58294HIGH8.8FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va...
CVE-2024-58293HIGH8.6Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec...
CVE-2024-58292MEDIUM5.3XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to...
CVE-2024-58291MEDIUM5.3Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject ma...
CVE-2024-58290CRITICAL9.3Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now