2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57764CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57763CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57762HIGH7.5MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CVE-2024-57761HIGH8.1An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut...
CVE-2024-57760MEDIUM6.5JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG...
CVE-2024-57757HIGH7.5JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c...
CVE-2024-57483CRITICAL9.8Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
CVE-2024-57473CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit...
CVE-2024-54730HIGH7.5Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
CVE-2024-54142CRITICAL9Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i...
CVE-2024-53277MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT...
CVE-2024-47605MEDIUM5.4silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional...
CVE-2024-42911HIGH7.4ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln...
CVE-2024-57482CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw...
CVE-2024-57480CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration...
CVE-2024-57479CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda...
CVE-2024-57471CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne...
CVE-2024-50861MEDIUM6.1The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod...
CVE-2024-50859MEDIUM4.8The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma...
CVE-2024-50858HIGH8.8Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio...
CVE-2024-50857MEDIUM4.8The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en...
CVE-2024-48760CRITICAL9.8An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke...
CVE-2024-45102MEDIUM6.8A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ...
CVE-2024-10254MEDIUM4.7A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al...
CVE-2024-10253MEDIUM4.7A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now