2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46869MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver...
CVE-2024-46510HIGH7.6ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax inter...
CVE-2024-46475MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at...
CVE-2024-47172MEDIUM5.4Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke...
CVE-2024-47064MEDIUM6.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an atta...
CVE-2024-47063MEDIUM6.1Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malic...
CVE-2024-46313HIGH8TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.
CVE-2024-46293CRITICAL9.8Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authori...
CVE-2024-46280HIGH8.8PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak c...
CVE-2024-45792MEDIUM6.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered...
CVE-2024-6051MEDIUM4.3Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection ...
CVE-2024-47641MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel C...
CVE-2024-45920MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts ...
CVE-2024-45772HIGH8Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replica...
CVE-2024-9329MEDIUM6.1In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the ...
CVE-2024-8459MEDIUM4.9Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, ...
CVE-2024-8458HIGH8.8Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-8457MEDIUM4.8Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,...
CVE-2024-8456CRITICAL9.8Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, a...
CVE-2024-8455MEDIUM5.9The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authe...
CVE-2024-8454HIGH7.5The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-...
CVE-2024-8453MEDIUM4.9Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salte...
CVE-2024-6394HIGH7.5A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to un...
CVE-2024-45200MEDIUM6.3In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e...
CVE-2024-42496LOW2.4Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now