2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39354HIGH7.8If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a sta...
CVE-2024-11070MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects...
CVE-2024-50263MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error...
CVE-2024-34015LOW3.3Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are...
CVE-2024-34014MEDIUM5.5Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Ac...
CVE-2024-10345HIGH8.7In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was ...
CVE-2024-10344HIGH8.7In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was id...
CVE-2024-10314HIGH8.7In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation functi...
CVE-2024-43437MEDIUM6.1A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scrip...
CVE-2024-43435MEDIUM5.3A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries ...
CVE-2024-43433MEDIUM5.3A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Mo...
CVE-2024-43432MEDIUM5.3A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, bu...
CVE-2024-43430MEDIUM5.3A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
CVE-2024-43429MEDIUM5.3A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in user...
CVE-2024-43427LOW3.7A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are ...
CVE-2024-11068CRITICAL9.8The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attacke...
CVE-2024-11067HIGH7.5The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this ...
CVE-2024-11066HIGH7.2The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil...
CVE-2024-11065HIGH7.2The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil...
CVE-2024-11064HIGH7.2The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil...
CVE-2024-11063HIGH7.2The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil...
CVE-2024-11062HIGH7.2The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil...
CVE-2024-11021MEDIUM5.4Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can...
CVE-2024-11020CRITICAL9.8Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitr...
CVE-2024-52355MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM osm.This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now