2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-35050HIGH8.8An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was del...
CVE-2024-34974HIGH8.2Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
CVE-2024-34944HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 param...
CVE-2024-34942HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 p...
CVE-2024-34921HIGH8.8TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
CVE-2024-34818HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.1...
CVE-2024-34559HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from ...
CVE-2024-34459HIGH7.5An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with...
CVE-2024-34440HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect...
CVE-2024-34433HIGH7.2Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: ...
CVE-2024-34431HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etr...
CVE-2024-34360HIGH8.2go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATX...
CVE-2024-34352HIGH7.51Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many ...
CVE-2024-34351HIGH7.5Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery ...
CVE-2024-34350HIGH7.5Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsiste...
CVE-2024-34345HIGH8.1The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML Extern...
CVE-2024-34338HIGH7.2Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest p...
CVE-2024-34310HIGH8.8Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id param...
CVE-2024-34308HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the funct...
CVE-2024-34231HIGH7.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-34224HIGH7.3Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using P...
CVE-2024-34221HIGH8.8Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalat...
CVE-2024-34220HIGH7.5Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
CVE-2024-34219HIGH8.6TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allo...
CVE-2024-34217HIGH7.7TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now