2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53470MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA...
CVE-2024-12247MEDIUM4.3Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat...
CVE-2024-12232MEDIUM6.1A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner...
CVE-2024-12231CRITICAL9.8A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an ...
CVE-2024-10716MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
CVE-2024-12230CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affecte...
CVE-2024-12229CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnera...
CVE-2024-11942MEDIUM5.9A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.
CVE-2024-11941HIGH7.5A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, fr...
CVE-2024-54679MEDIUM6.5CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
CVE-2024-53703HIGH8.1A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by...
CVE-2024-53702MEDIUM5.3Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup ...
CVE-2024-52271HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display...
CVE-2024-45319MEDIUM6.3A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authentica...
CVE-2024-45318HIGH8.1A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buf...
CVE-2024-40763HIGH7.5Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote aut...
CVE-2024-12228CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unkn...
CVE-2024-12227MEDIUM6.8A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the f...
CVE-2024-6784CRITICAL9.9Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and un...
CVE-2024-6516MEDIUM6.1Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a clien...
CVE-2024-6515HIGH8.1Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher p...
CVE-2024-54127MEDIUM4.3This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without pro...
CVE-2024-54126HIGH8.5This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg...
CVE-2024-51555CRITICAL10Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since ...
CVE-2024-51554CRITICAL9.8Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default cred...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now