2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56517MEDIUM5.3LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con...
CVE-2024-56516MEDIUM6.9free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f...
CVE-2024-52294MEDIUM4.3Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR...
CVE-2024-12836HIGH7.8Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-12835HIGH7.8Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabilit...
CVE-2024-12834HIGH7.8Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-12828HIGH8.8Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ...
CVE-2024-12754MEDIUM5.5AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi...
CVE-2024-50703HIGH8.1TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
CVE-2024-50702MEDIUM5.3TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis...
CVE-2024-50701MEDIUM4.3TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a...
CVE-2024-54181HIGH7.2IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to exe...
CVE-2024-10044CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro...
CVE-2024-12993MEDIUM4.8Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta...
CVE-2024-47926CRITICAL9.8Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-47925HIGH7.5Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47924HIGH7.5Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47923MEDIUM5.3Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-47922HIGH7.5Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-47921HIGH8.4Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CVE-2024-47920HIGH7.5Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47919CRITICAL9.8Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47918MEDIUM6.1Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-47917HIGH7.5CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-22063CRITICAL9The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can expl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now