2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12646HIGH8.1The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local...
CVE-2024-12645MEDIUM6.5The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w...
CVE-2024-12644HIGH7.1The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser...
CVE-2024-12643HIGH8.1The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ...
CVE-2024-12642HIGH8.1TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca...
CVE-2024-12641CRITICAL9.6TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a si...
CVE-2024-5333MEDIUM5.3The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat...
CVE-2024-56112MEDIUM6.1CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-56087MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template...
CVE-2024-56086HIGH7.1An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are...
CVE-2024-56085MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template...
CVE-2024-56084HIGH7.1An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea...
CVE-2024-11841MEDIUM5.4The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be...
CVE-2024-8650MEDIUM5.3An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6...
CVE-2024-8116MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17....
CVE-2024-53376HIGH8.8CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ...
CVE-2024-56083HIGH8.1Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly...
CVE-2024-8798MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-11858HIGH7.8A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation wh...
CVE-2024-7701HIGH7.5Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption B...
CVE-2024-56082LOW3.5ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab...
CVE-2024-56074MEDIUM5.5gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
CVE-2024-55969CRITICAL9.1DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX do...
CVE-2024-56073HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote...
CVE-2024-56072HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to ca...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now