2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9171Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-8630CRITICAL9.8Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
CVE-2024-8310CRITICAL9.8OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full...
CVE-2024-6981CRITICAL9.8OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without pro...
CVE-2024-46367CRITICAL9.6A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary...
CVE-2024-46366HIGH8.8A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbi...
CVE-2024-38809MEDIUM5.3Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of...
CVE-2024-22170CRITICAL9.2Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-s...
CVE-2024-6983HIGH8.8mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backe...
CVE-2024-47077MEDIUM6.5authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl...
CVE-2024-47070CRITICAL9authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 al...
CVE-2024-45745MEDIUM4.3TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute Jav...
CVE-2024-45744MEDIUM4.3TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r...
CVE-2024-46472HIGH8.6CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
CVE-2024-46471HIGH7.5The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conten...
CVE-2024-46470MEDIUM6.1Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaS...
CVE-2024-46333MEDIUM4.8An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc...
CVE-2024-46331HIGH7.2ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. T...
CVE-2024-44912HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
CVE-2024-44911HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).
CVE-2024-44910HIGH7.5NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
CVE-2024-40510HIGH8.2Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-40509HIGH7.3Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t...
CVE-2024-3373CRITICAL9.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website...
CVE-2024-9283MEDIUM4.8A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now