2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10086MEDIUM6.1A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Co...
CVE-2024-10006MEDIUM5.8A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentio...
CVE-2024-10005MEDIUM5.8A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intent...
CVE-2024-51427CRITICAL9.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51426HIGH8.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51425HIGH8.8An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ...
CVE-2024-51424CRITICAL9.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51419MEDIUM6.1Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibiti...
CVE-2024-51243HIGH7.2The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy...
CVE-2024-51242MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployControl...
CVE-2024-48807MEDIUM5.4Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to e...
CVE-2024-48735HIGH7.7Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ...
CVE-2024-48734HIGH8.8Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta...
CVE-2024-48733HIGH8.8SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e...
CVE-2024-48346MEDIUM6.1xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerab...
CVE-2024-48112CRITICAL9.8A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to ...
CVE-2024-48093HIGH8Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe...
CVE-2024-43382MEDIUM5.9Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being u...
CVE-2024-48272MEDIUM6.5D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers t...
CVE-2024-48271HIGH8.8D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ...
CVE-2024-10546MEDIUM6.3A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects u...
CVE-2024-48202CRITICAL9.8icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
CVE-2024-46531MEDIUM6.3phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchi...
CVE-2024-9419CRITICAL9.8Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Exec...
CVE-2024-48648MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now