2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35050 | HIGH | 8.8 | 0.7% | May 14, 2024 | An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was del... |
| CVE-2024-34974 | HIGH | 8.2 | 0.7% | May 14, 2024 | Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter. |
| CVE-2024-34944 | HIGH | 8.8 | 0.4% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 param... |
| CVE-2024-34942 | HIGH | 8.8 | 0.9% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 p... |
| CVE-2024-34921 | HIGH | 8.8 | 9.3% | May 14, 2024 | TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function. |
| CVE-2024-34818 | HIGH | 7.1 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.1... |
| CVE-2024-34559 | HIGH | 7.5 | 0.7% | May 14, 2024 | Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from ... |
| CVE-2024-34459 | HIGH | 7.5 | 2.3% | May 14, 2024 | An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with... |
| CVE-2024-34440 | HIGH | 7.2 | 0.8% | May 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect... |
| CVE-2024-34433 | HIGH | 7.2 | 0.5% | May 14, 2024 | Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: ... |
| CVE-2024-34431 | HIGH | 7.1 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etr... |
| CVE-2024-34360 | HIGH | 8.2 | 0.7% | May 14, 2024 | go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATX... |
| CVE-2024-34352 | HIGH | 7.5 | 1.3% | May 14, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many ... |
| CVE-2024-34351 | HIGH | 7.5 | 5.5% | May 14, 2024 | Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery ... |
| CVE-2024-34350 | HIGH | 7.5 | 1.2% | May 14, 2024 | Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsiste... |
| CVE-2024-34345 | HIGH | 8.1 | 0.9% | May 14, 2024 | The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML Extern... |
| CVE-2024-34338 | HIGH | 7.2 | 2.8% | May 14, 2024 | Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest p... |
| CVE-2024-34310 | HIGH | 8.8 | 0.9% | May 14, 2024 | Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id param... |
| CVE-2024-34308 | HIGH | 8.8 | 0.6% | May 14, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the funct... |
| CVE-2024-34231 | HIGH | 7.1 | 0.5% | May 14, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-34224 | HIGH | 7.3 | 0.9% | May 14, 2024 | Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using P... |
| CVE-2024-34221 | HIGH | 8.8 | 0.8% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalat... |
| CVE-2024-34220 | HIGH | 7.5 | 0.8% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter. |
| CVE-2024-34219 | HIGH | 8.6 | 20.8% | May 14, 2024 | TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allo... |
| CVE-2024-34217 | HIGH | 7.7 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now