2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52300CRITICAL9macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't ...
CVE-2024-52299HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService...
CVE-2024-52298HIGH7.5macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an...
CVE-2024-52295CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and...
CVE-2024-52293HIGH7.2Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi...
CVE-2024-50972HIGH7.2A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker...
CVE-2024-50971HIGH7.2A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to...
CVE-2024-50970HIGH8.8A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta...
CVE-2024-50969MEDIUM6.1A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote atta...
CVE-2024-11175MEDIUM4.8A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces...
CVE-2024-10013HIGH7.8In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through...
CVE-2024-10012HIGH7.8In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i...
CVE-2024-9477MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air...
CVE-2024-50854HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
CVE-2024-50853HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
CVE-2024-50852HIGH8.8Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ...
CVE-2024-49506HIGH7.3Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se...
CVE-2024-49505MEDIUM6.1A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumblew...
CVE-2024-49504HIGH7grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
CVE-2024-48900MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi...
CVE-2024-48510CRITICAL9.8Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi...
CVE-2024-11165MEDIUM5.7An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in ...
CVE-2024-48989HIGH7.5A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke...
CVE-2024-11159MEDIUM4.3Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T...
CVE-2024-47574HIGH7.8A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now