2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48343MEDIUM6.3A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id para...
CVE-2024-8036MEDIUM5.9ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exp...
CVE-2024-48743MEDIUM6.5Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parame...
CVE-2024-48655HIGH8.8An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
CVE-2024-48654MEDIUM6.1Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2024-48459HIGH7.3A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jix...
CVE-2024-10387HIGH7.5CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow...
CVE-2024-10386CRITICAL9.8CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a...
CVE-2024-48581CRITICAL9.8File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary c...
CVE-2024-48580CRITICAL9.8SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary...
CVE-2024-48579CRITICAL9.8SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to exec...
CVE-2024-48204CRITICAL9.8SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary...
CVE-2024-49757MEDIUM4.9The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Du...
CVE-2024-48428CRITICAL9.8An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
CVE-2024-49753CRITICAL9.1Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59....
CVE-2024-49381HIGH7.5Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLoca...
CVE-2024-49380HIGH7.5Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` ...
CVE-2024-9991HIGH7This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the devic...
CVE-2024-49378MEDIUM6.1smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox vers...
CVE-2024-49376HIGH8.8Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password ...
CVE-2024-10381CRITICAL9.8This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management...
CVE-2024-10380HIGH7.5A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0....
CVE-2024-10379HIGH7.5A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function ac...
CVE-2024-10378CRITICAL9.8A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile...
CVE-2024-10374MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now