2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9570HIGH8.8A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function ...
CVE-2024-46446CRITICAL9.8Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identi...
CVE-2024-46278HIGH8.4Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
CVE-2024-46041HIGH8.8IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.
CVE-2024-46040MEDIUM6.5IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation...
CVE-2024-45932MEDIUM4.8Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz...
CVE-2024-28710MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code ...
CVE-2024-28709MEDIUM6.1Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code...
CVE-2024-9576HIGH7.8Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the net...
CVE-2024-9574MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could a...
CVE-2024-9573MEDIUM6.5SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which cou...
CVE-2024-9572MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-9571MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan...
CVE-2024-9569HIGH8.8A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is ...
CVE-2024-9568HIGH8.8A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAd...
CVE-2024-45933MEDIUM6.6OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the...
CVE-2024-9567HIGH8.8A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the fun...
CVE-2024-9566HIGH8.8A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function for...
CVE-2024-46325MEDIUM5.5TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.
CVE-2024-45153MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-43047HIGH7.8Memory corruption while maintaining memory maps of HLOS memory.
CVE-2024-42027MEDIUM6.7The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to ...
CVE-2024-38425MEDIUM6.1Information disclosure while sending implicit broadcast containing APP launch information.
CVE-2024-38399HIGH7.8Memory corruption while processing user packets to generate page faults.
CVE-2024-38397HIGH7.5Transient DOS while parsing probe response and assoc response frame.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now