2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12914MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR...
CVE-2024-32832CRITICAL9.8Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L...
CVE-2024-32589HIGH7.1Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager ...
CVE-2024-46484CRITICAL9.8TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser...
CVE-2024-12923MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user ...
CVE-2024-46917HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur...
CVE-2024-46916HIGH8.1Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys...
CVE-2024-13342CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-13987MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Se...
CVE-2024-54568MEDIUM4.3The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously ...
CVE-2024-54554MEDIUM5.5This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be ab...
CVE-2024-44271LOW3.3The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record th...
CVE-2024-13986HIGH8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an...
CVE-2024-48908MEDIUM6.9lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there i...
CVE-2024-49790MEDIUM5.4IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an ...
CVE-2024-58240HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling ...
CVE-2024-13807HIGH7.5The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-9648MEDIUM6.1The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i...
CVE-2024-13985CRITICAL10A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe...
CVE-2024-13984CRITICAL10QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the...
CVE-2024-13982HIGH8.7SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar...
CVE-2024-13981CRITICAL10LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb...
CVE-2024-13980CRITICAL10H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulner...
CVE-2024-13979CRITICAL9.8A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers ...
CVE-2024-37777HIGH8.8O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now