2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-14021HIGH7.8LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability i...
CVE-2024-30547HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea...
CVE-2024-53735HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We...
CVE-2024-30516HIGH7.5Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio...
CVE-2024-30461HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc ...
CVE-2024-58337HIGH8.7Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to...
CVE-2024-58336HIGH8.7Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video s...
CVE-2024-58315HIGH8.5Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to pote...
CVE-2024-25183HIGH7.5givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.
CVE-2024-30855HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act...
CVE-2024-9684HIGH7.5FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me...
CVE-2024-24844HIGH7.5Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi...
CVE-2024-46062HIGH7.8Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t...
CVE-2024-46060HIGH7.8Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th...
CVE-2024-29371HIGH7.5In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry...
CVE-2024-44599HIGH8.3FNT Command 13.4.0 is vulnerable to Directory Traversal.
CVE-2024-44598HIGH8.8FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2024-58316HIGH8.7Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows...
CVE-2024-58314HIGH8.8Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi...
CVE-2024-58305HIGH8.8WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu...
CVE-2024-58313HIGH7.2xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr...
CVE-2024-58312HIGH7.5xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ...
CVE-2024-58310HIGH8.7APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se...
CVE-2024-58307HIGH8.8CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent...
CVE-2024-58306HIGH8.7minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now