2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53304MEDIUM6.5An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and ...
CVE-2024-53303HIGH8.8A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al...
CVE-2024-40074MEDIUM4.8Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat...
CVE-2024-40073CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p...
CVE-2024-40072CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2024-40071CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge...
CVE-2024-40070MEDIUM5.1Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge...
CVE-2024-40069MEDIUM5.4Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat...
CVE-2024-40068MEDIUM5.9Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2024-22314HIGH7.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c...
CVE-2024-58249LOW3.7In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL.
CVE-2024-56736MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):...
CVE-2024-58097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor d...
CVE-2024-58096MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng->lock for ath11k_hal_srng_* ...
CVE-2024-58095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call ...
CVE-2024-58094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_t...
CVE-2024-58093HIGH7.8In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea...
CVE-2024-58248LOW3.5nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red...
CVE-2024-46915——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-58092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Ge...
CVE-2024-52281HIGH8.9A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to...
CVE-2024-22036CRITICAL9.1A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail...
CVE-2024-10680MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could ...
CVE-2024-13452MEDIUM6.1The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-49200MEDIUM6.4An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now