2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43705HIGH7.8Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only sy...
CVE-2024-54775MEDIUM4.8Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /adm...
CVE-2024-54774MEDIUM4.8Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.
CVE-2024-50714HIGH7.5A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive ...
CVE-2024-50717CRITICAL9.8SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client par...
CVE-2024-50716CRITICAL9.8SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id paramet...
CVE-2024-50715HIGH7.5An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command inje...
CVE-2024-50713CRITICAL9.8SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.
CVE-2024-56732CRITICAL9.3HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c...
CVE-2024-54454MEDIUM5.3An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0...
CVE-2024-54453HIGH7.5An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0...
CVE-2024-54452MEDIUM4.9An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal ...
CVE-2024-54451MEDIUM4.8A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0....
CVE-2024-54450CRITICAL9.4An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica...
CVE-2024-39025HIGH7.5Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
CVE-2024-12991MEDIUM5.3A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as pr...
CVE-2024-53476MEDIUM5.9A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to b...
CVE-2024-50945HIGH7.5An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all...
CVE-2024-50944CRITICAL9.8Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shoppin...
CVE-2024-12990MEDIUM5.3A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown ...
CVE-2024-12989MEDIUM6.9A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is s...
CVE-2024-12988HIGH7.5A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne...
CVE-2024-56509HIGH8.6changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2024-56508HIGH7.6LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit...
CVE-2024-56507MEDIUM5.4LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now