2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-34145HIGH8.8A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen...
CVE-2024-33303HIGH8.2SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.
CVE-2024-30251HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can sen...
CVE-2024-23462HIGH7.5An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of se...
CVE-2024-33911HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Ma...
CVE-2024-32114HIGH8.8In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and...
CVE-2024-3476HIGH8.8The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow atta...
CVE-2024-3475HIGH7.5The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow atta...
CVE-2024-3474HIGH8.8The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow at...
CVE-2024-33423HIGH7.4Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary we...
CVE-2024-33306HIGH7.4SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter i...
CVE-2024-33430HIGH8.8An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ...
CVE-2024-33429HIGH7.1Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary cod...
CVE-2024-33428HIGH8.8Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ...
CVE-2024-33300HIGH7.3Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows ...
CVE-2024-33292HIGH8.2SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the i...
CVE-2024-29011HIGH7.5Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects G...
CVE-2024-26504HIGH8.8An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst pa...
CVE-2024-25458HIGH7.5An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0...
CVE-2024-25355HIGH7.5s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.
CVE-2024-24313HIGH7.5An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Mode...
CVE-2024-24312HIGH7.5SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive infor...
CVE-2024-32212HIGH8.1SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute ar...
CVE-2024-29010HIGH7.1The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially...
CVE-2024-33517HIGH7.5An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now