2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49399HIGH8.7The affected product is vulnerable to an attacker being able to use commands without providing a password which may allo...
CVE-2024-49398HIGH8.8The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
CVE-2024-49397CRITICAL9.2The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication...
CVE-2024-49396HIGH8.7The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersona...
CVE-2024-48192HIGH8Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which a...
CVE-2024-10073HIGH7.5A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function Clusteri...
CVE-2024-10072HIGH8.8A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function act...
CVE-2024-9414HIGH7In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code...
CVE-2024-10071HIGH8.8A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdate...
CVE-2024-9683MEDIUM5.3A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is prov...
CVE-2024-48920CRITICAL9.1PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constr...
CVE-2024-47459MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ...
CVE-2024-10070HIGH8.8A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of t...
CVE-2024-10069HIGH8.8A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actio...
CVE-2024-6333HIGH7.2Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
CVE-2024-49315HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD ...
CVE-2024-49580MEDIUM5.3In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
CVE-2024-49579MEDIUM6.1In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized...
CVE-2024-48048HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in GabbyKhrmon Wsify Widget wsify-widget allows Stored XSS.This issue af...
CVE-2024-48046MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact ...
CVE-2024-48037MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Si...
CVE-2024-48036MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B...
CVE-2024-48032HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Feature...
CVE-2024-48031MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) feature...
CVE-2024-48025MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Base...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now