2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41512HIGH8.8A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attacker...
CVE-2024-41511LOW3.9A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allo...
CVE-2024-38040HIGH7.5There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthen...
CVE-2024-38039MEDIUM5.4There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, auth...
CVE-2024-38038MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 which may allow a remote, unauthenticated...
CVE-2024-38037MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthe...
CVE-2024-38036MEDIUM5.4There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, una...
CVE-2024-25707MEDIUM4.8There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a rem...
CVE-2024-25702MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 11.1 and below ...
CVE-2024-25701MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Experience Builder versions 11...
CVE-2024-25694MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise versions 11.1 and below that m...
CVE-2024-25691MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unaut...
CVE-2024-46486HIGH8TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv fu...
CVE-2024-46409MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts o...
CVE-2024-47769HIGH7.5IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. U...
CVE-2024-47768HIGH8.1Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to ...
CVE-2024-47765MEDIUM6.1Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential c...
CVE-2024-47183HIGH8.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser...
CVE-2024-9515HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function...
CVE-2024-9514HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects ...
CVE-2024-9410MEDIUM5.3Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping ...
CVE-2024-9513LOW3.7A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this is...
CVE-2024-9484MEDIUM5.5An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on Ma...
CVE-2024-9483MEDIUM5.5A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 2...
CVE-2024-9482MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now