2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35582 | MEDIUM | 6.1 | 0.4% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-35581 | MEDIUM | 6.1 | 0.4% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-28061 | MEDIUM | 6.3 | 0.3% | May 28, 2024 | An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data st... |
| CVE-2024-5434 | MEDIUM | 6.9 | 0.2% | May 28, 2024 | The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwo... |
| CVE-2024-5433 | MEDIUM | 5.3 | 0.5% | May 28, 2024 | The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given exp... |
| CVE-2024-36107 | MEDIUM | 5.3 | 0.5% | May 28, 2024 | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` an... |
| CVE-2024-35401 | MEDIUM | 5.9 | 0.7% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName para... |
| CVE-2024-35342 | MEDIUM | 4.6 | 0.2% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volu... |
| CVE-2024-34852 | MEDIUM | 6.3 | 1.6% | May 28, 2024 | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point ... |
| CVE-2024-30164 | MEDIUM | 6.7 | 0.3% | May 28, 2024 | Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wit... |
| CVE-2024-36472 | MEDIUM | 6.5 | 0.3% | May 28, 2024 | In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network ... |
| CVE-2024-35621 | MEDIUM | 4.8 | 0.3% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute ar... |
| CVE-2024-33849 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key. |
| CVE-2024-33807 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management Syst... |
| CVE-2024-33804 | MEDIUM | 6.3 | 0.3% | May 28, 2024 | A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-33803 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows... |
| CVE-2024-33802 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System... |
| CVE-2024-35400 | MEDIUM | 5.3 | 0.5% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function... |
| CVE-2024-2451 | MEDIUM | 6.4 | 0.1% | May 28, 2024 | Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows ... |
| CVE-2024-5428 | MEDIUM | 4.3 | 0.3% | May 28, 2024 | A vulnerability classified as problematic was found in SourceCodester Simple Online Bidding System 1.0. Affected by this... |
| CVE-2024-24584 | MEDIUM | 4.3 | 0.5% | May 28, 2024 | Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms... |
| CVE-2024-24583 | MEDIUM | 4.3 | 0.5% | May 28, 2024 | Multiple out-of-bounds read vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .ms... |
| CVE-2024-5413 | MEDIUM | 6.1 | 0.3% | May 28, 2024 | A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS... |
| CVE-2024-2199 | MEDIUM | 5.7 | 0.5% | May 28, 2024 | A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to ca... |
| CVE-2024-28793 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configur... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now