2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10093HIGH7.8A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown funct...
CVE-2024-33453HIGH8.1Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the external...
CVE-2024-30875HIGH7.1Cross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive...
CVE-2024-48924HIGH8.7### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a den...
CVE-2024-49283HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY w...
CVE-2024-49278HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omni...
CVE-2024-49276HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cliogrow Clio Grow...
CVE-2024-49248HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inser...
CVE-2024-7755HIGH8.2The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network ...
CVE-2024-49316HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zodiac Akismet hta...
CVE-2024-49309HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omarfolghe Digital...
CVE-2024-49308HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Anim...
CVE-2024-10100HIGH7.5A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper ha...
CVE-2024-49317HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-49313HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in rudestan VKontakte Wall Post vkontakte-wall-post allows Stored XSS.Th...
CVE-2024-49312HIGH8.6Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser B...
CVE-2024-49299HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer Surfer surf...
CVE-2024-49297HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM L...
CVE-2024-49287HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Re...
CVE-2024-49285HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Mail...
CVE-2024-49244HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vrinsoft CSV Produ...
CVE-2024-49235HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video ...
CVE-2024-49219HIGH8.8Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue af...
CVE-2024-48638HIGH8D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via th...
CVE-2024-48637HIGH8D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now