2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47464MEDIUM6.8An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulner...
CVE-2024-47463HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47462HIGH7.2An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo...
CVE-2024-47461HIGH7.2An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes...
CVE-2024-47460CRITICAL9Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sen...
CVE-2024-42509CRITICAL9.8Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sen...
CVE-2024-51756LOW2.3The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write c...
CVE-2024-51745CRITICAL10Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks ac...
CVE-2024-51116HIGH8.8Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
CVE-2024-10084MEDIUM4.3The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all ve...
CVE-2024-7995HIGH7.8A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a...
CVE-2024-51753LOW2.1The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthK...
CVE-2024-51752MEDIUM5.5The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2024-51746LOW1.8Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the...
CVE-2024-51740HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests o...
CVE-2024-51735HIGH8.7Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when ...
CVE-2024-51493MEDIUM6.5OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10....
CVE-2024-51382HIGH8.4Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password...
CVE-2024-51381HIGH8.4Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for ad...
CVE-2024-51380HIGH8.4Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows...
CVE-2024-51379HIGH8.4Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description ...
CVE-2024-51240HIGH8An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root v...
CVE-2024-50335MEDIUM5.4SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish K...
CVE-2024-50333HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is ...
CVE-2024-50332HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now