2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-30855HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_act...
CVE-2024-9684HIGH7.5FreyrSCADA/IEC-60870-5-104 server v21.06.008 allows remote attackers to cause a denial of service by sending specific me...
CVE-2024-24844HIGH7.5Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Confi...
CVE-2024-46062HIGH7.8Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t...
CVE-2024-46060HIGH7.8Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th...
CVE-2024-29371HIGH7.5In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry...
CVE-2024-44599HIGH8.3FNT Command 13.4.0 is vulnerable to Directory Traversal.
CVE-2024-44598HIGH8.8FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2024-58316HIGH8.7Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows...
CVE-2024-58314HIGH8.8Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi...
CVE-2024-58305HIGH8.8WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu...
CVE-2024-58313HIGH7.2xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr...
CVE-2024-58312HIGH7.5xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system ...
CVE-2024-58310HIGH8.7APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se...
CVE-2024-58307HIGH8.8CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent...
CVE-2024-58306HIGH8.7minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending...
CVE-2024-58303HIGH8.6FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject...
CVE-2024-58300HIGH8.7Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac...
CVE-2024-58295HIGH8.6ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma...
CVE-2024-58294HIGH8.8FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va...
CVE-2024-58293HIGH8.6Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec...
CVE-2024-58288HIGH8.7Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service...
CVE-2024-58287HIGH8.8reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all...
CVE-2024-8273HIGH8.8Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor...
CVE-2024-58284HIGH7.2PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now