2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38512HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38511HIGH7.2A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut...
CVE-2024-38510HIGH7.2A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe...
CVE-2024-38509HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38508HIGH7.2A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t...
CVE-2024-39304HIGH8.8ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au...
CVE-2024-38872HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-38871HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-41813HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ...
CVE-2024-41812HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ...
CVE-2024-41354HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
CVE-2024-41353HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
CVE-2024-24257HIGH7.5An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen...
CVE-2024-7050HIGH8.3Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa...
CVE-2024-41357HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
CVE-2024-41670HIGH7.5In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ...
CVE-2024-41692HIGH8.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte...
CVE-2024-7062HIGH7.8Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged...
CVE-2024-41687HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ...
CVE-2024-41685HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass...
CVE-2024-35296HIGH8.2Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This...
CVE-2024-35161HIGH7.5Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for reques...
CVE-2024-7119HIGH8.8A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System u...
CVE-2024-7118HIGH8.8A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Af...
CVE-2024-7117HIGH8.8A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 2023091...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now