2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-47976MEDIUM6.7Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to ...
CVE-2024-47972MEDIUM4Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the p...
CVE-2024-47971MEDIUM6.5Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.
CVE-2024-47079MEDIUM6.4Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht...
CVE-2024-45292MEDIUM5.4PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` ...
CVE-2024-31228MEDIUM6.5Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service b...
CVE-2024-31227MEDIUM4.4Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat...
CVE-2024-45894MEDIUM4.9BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
CVE-2024-44674MEDIUM5.7D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained thr...
CVE-2024-42831MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex...
CVE-2024-46300MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-46040MEDIUM6.5IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation...
CVE-2024-45932MEDIUM4.8Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz...
CVE-2024-28710MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code ...
CVE-2024-28709MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code...
CVE-2024-9574MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could a...
CVE-2024-9573MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which cou...
CVE-2024-9572MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-9571MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-45933MEDIUM6.6OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the...
CVE-2024-46325MEDIUM5.5TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.
CVE-2024-45153MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-42027MEDIUM6.7The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to ...
CVE-2024-38425MEDIUM6.1Information disclosure while sending implicit broadcast containing APP launch information.
CVE-2024-23379MEDIUM6.7Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now