2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38796MEDIUM5.9EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an over...
CVE-2024-23586HIGH7.5HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthen...
CVE-2024-9293HIGH8.8A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the ...
CVE-2024-9291MEDIUM5.4A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75...
CVE-2024-47186MEDIUM6.1Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2...
CVE-2024-46453MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execut...
CVE-2024-6436MEDIUM6.5An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user...
CVE-2024-9160MEDIUM5.4In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
CVE-2024-33369HIGH8.8Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary ...
CVE-2024-33368HIGH8.8An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method...
CVE-2024-9301HIGH7.5A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
CVE-2024-46257MEDIUM6.3A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacke...
CVE-2024-46256CRITICAL9.8A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add...
CVE-2024-46097HIGH8.1TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is create...
CVE-2024-39364HIGH7Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow f...
CVE-2024-39275HIGH8.8Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging req...
CVE-2024-38308MEDIUM6.1Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the ...
CVE-2024-37187MEDIUM5.7Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
CVE-2024-34542MEDIUM5.7Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login pr...
CVE-2024-28948HIGH8.8Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumve...
CVE-2024-25412MEDIUM6.1A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-25411MEDIUM6.1A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2024-9284HIGH7.1A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is...
CVE-2024-9273Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-9268Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now