2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11789HIGH7.8Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul...
CVE-2024-11787HIGH7.8Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul...
CVE-2024-53860HIGH8.6sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnera...
CVE-2024-53859HIGH7.5go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerab...
CVE-2024-53858MEDIUM6.5The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c...
CVE-2024-53260MEDIUM6.8Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first a...
CVE-2024-53855MEDIUM4.3Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management wit...
CVE-2024-53264MEDIUM5.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in ...
CVE-2024-47181HIGH7.5Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be trigger...
CVE-2024-41126CRITICAL9.6Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr...
CVE-2024-41125CRITICAL9.6Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr...
CVE-2024-9369CRITICAL9.6Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromis...
CVE-2024-7025HIGH8.8Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap...
CVE-2024-53254Rejected reason: This CVE is a duplicate of another CVE.
CVE-2024-11160Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-54004MEDIUM4.3Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects ...
CVE-2024-54003HIGH8Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting ...
CVE-2024-51228MEDIUM6.8An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R...
CVE-2024-37816MEDIUM4.2Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.
CVE-2024-31976HIGH8EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controll...
CVE-2024-21703MEDIUM6.4This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a...
CVE-2024-11860MEDIUM6.5A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af...
CVE-2024-53920HIGH7.8In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) ...
CVE-2024-52951HIGH8Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authent...
CVE-2024-46055MEDIUM4.8OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now