2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9085CRITICAL9.8A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue ...
CVE-2024-9082CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this iss...
CVE-2024-9081HIGH7.5A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...
CVE-2024-9080CRITICAL9.8A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an...
CVE-2024-9079CRITICAL9.8A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some...
CVE-2024-9078CRITICAL9.8A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability...
CVE-2024-9077MEDIUM5.4A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A...
CVE-2024-47226MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of t...
CVE-2024-9076HIGH8.8A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce...
CVE-2024-47221HIGH7.5CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
CVE-2024-47220Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-47219CRITICAL9.8An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
CVE-2024-47218CRITICAL9.8An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
CVE-2024-9075MEDIUM5.4A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera...
CVE-2024-47210HIGH8.8Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be...
CVE-2024-42323HIGH8.8SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating).  This vulnerability can only be ...
CVE-2024-9048MEDIUM6.1A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab...
CVE-2024-8680MEDIUM5.5The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2024-6787MEDIUM5.9This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it ...
CVE-2024-6786MEDIUM6.5The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the...
CVE-2024-6785HIGH7.1The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf...
CVE-2024-46649HIGH7.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
CVE-2024-46648HIGH7.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
CVE-2024-46647MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
CVE-2024-46646MEDIUM6.5eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now