2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10327HIGH8.1A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification respo...
CVE-2024-45259MEDIUM6.5An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte...
CVE-2024-45242HIGH7.8EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metachar...
CVE-2024-48454HIGH7.2An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via ...
CVE-2024-48427HIGH8.8A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated us...
CVE-2024-48145CRITICAL9.1A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to a...
CVE-2024-48144CRITICAL9.1A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attacke...
CVE-2024-48143CRITICAL9.1A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers t...
CVE-2024-48142HIGH7.5A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows at...
CVE-2024-48141HIGH7.5A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate a...
CVE-2024-48140HIGH7.5A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v...
CVE-2024-48139HIGH7.5A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all pre...
CVE-2024-47173MEDIUM5.5Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ...
CVE-2024-46998MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed...
CVE-2024-46996MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl...
CVE-2024-46995MEDIUM6.1baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4...
CVE-2024-46994MEDIUM5.4baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog p...
CVE-2024-48514CRITICAL9.8php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl...
CVE-2024-48442MEDIUM6.5Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2...
CVE-2024-48441HIGH8.8Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain...
CVE-2024-48440HIGH8.8Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered t...
CVE-2024-46478CRITICAL9.8HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
CVE-2024-38314MEDIUM5.9IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-...
CVE-2024-10338HIGH7.2A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this v...
CVE-2024-10337HIGH7.2A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now