2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42738HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42737HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42736HIGH7.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-5849HIGH7.1An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the...
CVE-2024-38502HIGH7.1An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affe...
CVE-2024-43140HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstr...
CVE-2024-43138HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Ma...
CVE-2024-37287HIGH7.2A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector ...
CVE-2024-35124HIGH7.5A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020...
CVE-2024-43135HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allow...
CVE-2024-43131HIGH7.5Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing ...
CVE-2024-43129HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs a...
CVE-2024-43128HIGH7.3Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Li...
CVE-2024-43121HIGH7.2Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: fr...
CVE-2024-40697HIGH7.5IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for ...
CVE-2024-38787HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers i...
CVE-2024-38749HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import all...
CVE-2024-38747HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Paym...
CVE-2024-38724HIGH7.1Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scrip...
CVE-2024-38699HIGH7.5Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Proper...
CVE-2024-37935HIGH7.5Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrain...
CVE-2024-41977HIGH8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM...
CVE-2024-41976HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM...
CVE-2024-41939HIGH8.8A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enfor...
CVE-2024-41908HIGH7.8A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of boun...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now