2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4227HIGH7.5In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forc...
CVE-2024-11870MEDIUM6.4The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-55577HIGH7Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file wh...
CVE-2024-13394MEDIUM6.4The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco...
CVE-2024-13334MEDIUM6.1The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ...
CVE-2024-57767HIGH8.6MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CVE-2024-57766CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57765HIGH7.5MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CVE-2024-57764CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57763CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57762HIGH7.5MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CVE-2024-57761HIGH8.1An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut...
CVE-2024-57760MEDIUM6.5JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG...
CVE-2024-57757HIGH7.5JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c...
CVE-2024-57483CRITICAL9.8Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
CVE-2024-57473CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit...
CVE-2024-54730HIGH7.5Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
CVE-2024-54142CRITICAL9Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i...
CVE-2024-53277MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT...
CVE-2024-47605MEDIUM5.4silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional...
CVE-2024-42911HIGH7.4ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln...
CVE-2024-57482CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw...
CVE-2024-57480CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration...
CVE-2024-57479CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda...
CVE-2024-57471CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now