2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37961HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codoc.Jp al...
CVE-2024-6281HIGH7.3A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `...
CVE-2024-40348HIGH8.2An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory...
CVE-2024-41122HIGH8.8Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t...
CVE-2024-41121HIGH8.8Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t...
CVE-2024-39906HIGH8.3A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app...
CVE-2024-40400HIGH8.8An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr...
CVE-2024-41600HIGH7.5Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive...
CVE-2024-41602HIGH8.8Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privilege...
CVE-2024-41601HIGH7.5Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive informatio...
CVE-2024-41492HIGH7.5A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-41281HIGH8.8Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
CVE-2024-39963HIGH8AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01...
CVE-2024-27489HIGH7.5An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
CVE-2024-37066HIGH8.8A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to ...
CVE-2024-41107HIGH8.1The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh...
CVE-2024-6906HIGH8.8A vulnerability was found in SourceCodester Record Management System 1.0 and classified as critical. This issue affects ...
CVE-2024-6905HIGH8.8A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as critical. This vulnerabi...
CVE-2024-6904HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Record Management System 1.0. This affect...
CVE-2024-41172HIGH7.5In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit ...
CVE-2024-32007HIGH7.5An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at...
CVE-2024-6903HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affect...
CVE-2024-6902HIGH8.8A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulner...
CVE-2024-6338HIGH8.8The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ paramete...
CVE-2024-40724HIGH7.8Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now