2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-33529HIGH7.2ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrativ...
CVE-2024-33526HIGH7.1A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7...
CVE-2024-35386HIGH7.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the m...
CVE-2024-4420HIGH7.5There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.  * An adversary can crash binari...
CVE-2024-4988HIGH7.5The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th...
CVE-2024-4435HIGH7.5When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered...
CVE-2024-4566HIGH7.1The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-4290HIGH7.1The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could all...
CVE-2024-5145HIGH8.8A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue a...
CVE-2024-34710HIGH7.1Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to ...
CVE-2024-35579HIGH7.7Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.
CVE-2024-35578HIGH8Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
CVE-2024-34949HIGH8.2SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Orde...
CVE-2024-34193HIGH7.5smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vu...
CVE-2024-31714HIGH7.5Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the L...
CVE-2024-29651HIGH8.1A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to ex...
CVE-2024-24293HIGH8.8A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the ...
CVE-2024-34948HIGH7.5An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to ...
CVE-2024-0401HIGH7.2ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and r...
CVE-2024-4151HIGH8.1An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any p...
CVE-2024-3482HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a...
CVE-2024-34953HIGH7.5An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supply...
CVE-2024-2835HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a...
CVE-2024-4287HIGH7.2In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. ...
CVE-2024-27312HIGH8.1Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now