2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50713CRITICAL9.8SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.
CVE-2024-56732CRITICAL9.3HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c...
CVE-2024-54454MEDIUM5.3An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0...
CVE-2024-54453HIGH7.5An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0...
CVE-2024-54452MEDIUM4.9An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal ...
CVE-2024-54451MEDIUM4.8A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0....
CVE-2024-54450CRITICAL9.4An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica...
CVE-2024-39025HIGH7.5Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
CVE-2024-12991MEDIUM5.3A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as pr...
CVE-2024-53476MEDIUM5.9A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to b...
CVE-2024-50945HIGH7.5An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all...
CVE-2024-50944CRITICAL9.8Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shoppin...
CVE-2024-12990MEDIUM5.3A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown ...
CVE-2024-12989MEDIUM6.9A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is s...
CVE-2024-12988HIGH7.5A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne...
CVE-2024-56509HIGH8.6changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2024-56508HIGH7.6LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit...
CVE-2024-56507MEDIUM5.4LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scr...
CVE-2024-12987CRITICAL9.8A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an ...
CVE-2024-12986CRITICAL9.8A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. Th...
CVE-2024-12856HIGH7.2The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. A...
CVE-2024-56675HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RC...
CVE-2024-56674MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocat...
CVE-2024-56673MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Do not call pmd dtor on vmemmap page tab...
CVE-2024-56672HIGH7In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now