2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42625HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add
CVE-2024-42624HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.
CVE-2024-42623HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1
CVE-2024-41651HIGH8.1An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func...
CVE-2024-41475HIGH8.8Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
CVE-2024-40500HIGH8.6Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute ar...
CVE-2024-42632HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.
CVE-2024-42631HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.
CVE-2024-42630HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-42629HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
CVE-2024-42628HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.
CVE-2024-42489HIGH8.8Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the...
CVE-2024-42485HIGH7.5Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` all...
CVE-2024-42481HIGH7.5Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skypo...
CVE-2024-39091HIGH8.8An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 al...
CVE-2024-36877HIGH8.2Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B...
CVE-2024-42477HIGH7.5llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buff...
CVE-2024-33535HIGH7.5An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local fil...
CVE-2024-27442HIGH7.8An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is int...
CVE-2024-7697HIGH7.5Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
CVE-2024-7694HIGH7.2ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with ...
CVE-2024-7693HIGH7.5Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing ...
CVE-2024-7661HIGH8.8A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problema...
CVE-2024-7659HIGH7.5A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function gen...
CVE-2024-7589HIGH8.1A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now