2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-42051HIGH7.8The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during...
CVE-2024-42050HIGH7The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during...
CVE-2024-7152HIGH8.8A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fro...
CVE-2024-6431HIGH8.8The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-6152HIGH8.8The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5...
CVE-2024-40433HIGH8.8Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view...
CVE-2024-41815HIGH7Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable ...
CVE-2024-41628HIGH7.5Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and ...
CVE-2024-40116HIGH8.1An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the expo...
CVE-2024-38512HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38511HIGH7.2A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut...
CVE-2024-38510HIGH7.2A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe...
CVE-2024-38509HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38508HIGH7.2A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t...
CVE-2024-39304HIGH8.8ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au...
CVE-2024-38872HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-38871HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-41813HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ...
CVE-2024-41812HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ...
CVE-2024-41354HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
CVE-2024-41353HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
CVE-2024-24257HIGH7.5An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen...
CVE-2024-7050HIGH8.3Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa...
CVE-2024-41357HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
CVE-2024-41670HIGH7.5In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now