2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8525CRITICAL10An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to...
CVE-2024-45514MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists i...
CVE-2024-45512MEDIUM5.4An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerabilit...
CVE-2024-53429HIGH7.5Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
CVE-2024-48747MEDIUM6.8An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
CVE-2024-29224CRITICAL9.8An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can ...
CVE-2024-28892CRITICAL9.8An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can...
CVE-2024-28027HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28026HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28025HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-21855CRITICAL9.8A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP re...
CVE-2024-21786HIGH7.2An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies ...
CVE-2024-11592CRITICAL9.8A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vu...
CVE-2024-7130MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Comput...
CVE-2024-7026HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informati...
CVE-2024-53426MEDIUM6.2A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-53425MEDIUM6.2A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue oc...
CVE-2024-11591CRITICAL9.8A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This...
CVE-2024-11089MEDIUM5.3The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-11088HIGH7.5The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-7016MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek In...
CVE-2024-11590CRITICAL9.8A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe...
CVE-2024-11589HIGH8.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne...
CVE-2024-11588HIGH7.5A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the ...
CVE-2024-11587MEDIUM6.1A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOption...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now