2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48908MEDIUM6.9lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i...
CVE-2024-49790MEDIUM5.4IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an ...
CVE-2024-58240HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ...
CVE-2024-13807HIGH7.5The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-9648MEDIUM6.1The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i...
CVE-2024-13985CRITICAL10A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe...
CVE-2024-13984CRITICAL10QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the...
CVE-2024-13982HIGH8.7SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar...
CVE-2024-13981CRITICAL10LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb...
CVE-2024-13980CRITICAL10H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulner...
CVE-2024-13979CRITICAL9.8A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers ...
CVE-2024-37777HIGH8.8O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
CVE-2024-49740MEDIUM5.5In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser...
CVE-2024-47192MEDIUM5.3An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker ...
CVE-2024-35203MEDIUM6.1Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part o...
CVE-2024-39335CRITICAL9.1Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed...
CVE-2024-47853HIGH8.8An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w...
CVE-2024-45753MEDIUM6.1In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value ...
CVE-2024-8860MEDIUM4.3The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-46413MEDIUM5.1Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild....
CVE-2024-46412MEDIUM6.5Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a cra...
CVE-2024-39923MEDIUM6.1An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer lin...
CVE-2024-48988HIGH7.6SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users...
CVE-2024-53499CRITICAL9.8Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.
CVE-2024-53496CRITICAL9.8Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive compone...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now