2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-58304HIGH7.5SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allo...
CVE-2024-58303HIGH8.6FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject...
CVE-2024-58300HIGH8.7Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac...
CVE-2024-58295HIGH8.6ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload ma...
CVE-2024-58294HIGH8.8FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va...
CVE-2024-58293HIGH8.6Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to exec...
CVE-2024-58288HIGH8.7Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service...
CVE-2024-58287HIGH8.8reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all...
CVE-2024-8273HIGH8.8Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: befor...
CVE-2024-58284HIGH7.2PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inj...
CVE-2024-58283HIGH8.8WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali...
CVE-2024-58282HIGH7.2Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali...
CVE-2024-58281HIGH8.8Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP...
CVE-2024-58280HIGH8.8CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file exten...
CVE-2024-58279HIGH8.8appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo...
CVE-2024-2104HIGH8.8Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read a...
CVE-2024-56840HIGH7.5A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56839HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56838HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56837HIGH8.6A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56836HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-56835HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2024-58278HIGH8.5perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to exec...
CVE-2024-58277HIGH8.7R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the sys...
CVE-2024-58276HIGH8.7Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now