2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53701LOW3.1Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications...
CVE-2024-39162MEDIUM6.1pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported ...
CVE-2024-11980HIGH8.6Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem...
CVE-2024-10980MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress ...
CVE-2024-10704MEDIUM4.8The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul...
CVE-2024-48651HIGH7.5In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th...
CVE-2024-45495MEDIUM4.3MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
CVE-2024-35451MEDIUM4.8LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
CVE-2024-54124HIGH8.8In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
CVE-2024-54123MEDIUM6.1Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text...
CVE-2024-11979CRITICAL9.8DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This all...
CVE-2024-11978HIGH7.5DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ...
CVE-2024-9852HIGH7.8Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-8300HIGH7Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsub...
CVE-2024-8299HIGH7.8Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E...
CVE-2024-11971MEDIUM5.4A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab...
CVE-2024-11970CRITICAL9.8A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is a...
CVE-2024-11968HIGH7.5A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulner...
CVE-2024-11967CRITICAL9.8A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is...
CVE-2024-11966CRITICAL9.8A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects s...
CVE-2024-52338CRITICAL9.8Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0...
CVE-2024-11965CRITICAL9.8A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerabil...
CVE-2024-11964CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects...
CVE-2024-11969HIGH8.8The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili...
CVE-2024-11963HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now