2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53276MEDIUM6.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a...
CVE-2024-53275MEDIUM5.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, t...
CVE-2024-40896CRITICAL9.1In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa...
CVE-2024-56364MEDIUM5.4SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, w...
CVE-2024-56326HIGH7.8Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca...
CVE-2024-56201HIGH8.8Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo...
CVE-2024-55947HIGH8.8Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser...
CVE-2024-54148CRITICAL9.8Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a ...
CVE-2024-53256HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code ...
CVE-2024-45387HIGH8.8An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with...
CVE-2024-23945MEDIUM5.9Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authentici...
CVE-2024-55539LOW2.5Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) ...
CVE-2024-12903HIGH7.8Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl...
CVE-2024-12902HIGH8.4ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows...
CVE-2024-11230MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ p...
CVE-2024-12901MEDIUM6.9A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct...
CVE-2024-12900CRITICAL9.8A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /...
CVE-2024-54082HIGH7.2home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio...
CVE-2024-52321MEDIUM5.9Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc...
CVE-2024-47864MEDIUM5.3home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug...
CVE-2024-46873CRITICAL9.8Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root pr...
CVE-2024-45721HIGH7.2home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n...
CVE-2024-12899CRITICAL9.8A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. Thi...
CVE-2024-12898CRITICAL9.8A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. ...
CVE-2024-56378MEDIUM4.3libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now