2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-22311HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply S...
CVE-2024-22300HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subs...
CVE-2024-22299HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Makin...
CVE-2024-22149HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bas...
CVE-2024-2203HIGH8.8The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2024-2097HIGH7.5An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM serv...
CVE-2024-25736HIGH7.5An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d...
CVE-2024-25734HIGH7.5An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only a...
CVE-2024-25395HIGH8.8A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.
CVE-2024-25391HIGH8.4A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.
CVE-2024-25390HIGH8.4A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.
CVE-2024-25389HIGH7.5RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (see...
CVE-2024-25388HIGH8.4drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.
CVE-2024-24335HIGH8.4A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.
CVE-2024-24334HIGH8.4A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.
CVE-2024-0400HIGH7.5SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SC...
CVE-2024-1531HIGH8.2A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A...
CVE-2024-2932HIGH7.5A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unkno...
CVE-2024-26577HIGH7.5VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet co...
CVE-2024-25136HIGH7.5 There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL witho...
CVE-2024-2910HIGH8.8A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this is...
CVE-2024-2909HIGH8.8A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is th...
CVE-2024-2903HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetPare...
CVE-2024-2887HIGH7.7Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary cod...
CVE-2024-2886HIGH7.5Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now