2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46645HIGH7.5eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
CVE-2024-46644MEDIUM6.5eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
CVE-2024-46640CRITICAL9.8SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check...
CVE-2024-46103CRITICAL9.8SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
CVE-2024-46101CRITICAL9.8GDidees CMS <= v3.9.1 has a file upload vulnerability.
CVE-2024-45793MEDIUM4.8Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll...
CVE-2024-47062HIGH8.8Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t...
CVE-2024-47061HIGH8.3Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text ...
CVE-2024-46654MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at...
CVE-2024-45229MEDIUM6.6The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,...
CVE-2024-42351CRITICAL9.1Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ...
CVE-2024-42346MEDIUM5.4Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ...
CVE-2024-8612LOW3.8A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set ...
CVE-2024-42697MEDIUM6.1Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to...
CVE-2024-9041HIGH8.8A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Thi...
CVE-2024-9040MEDIUM5.5A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This ...
CVE-2024-45489CRITICAL9.8Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by ...
CVE-2024-37879MEDIUM4.8Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato...
CVE-2024-9039CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System ...
CVE-2024-9038CRITICAL9.8A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerabili...
CVE-2024-9037HIGH7.3A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown...
CVE-2024-9036MEDIUM6.3A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u...
CVE-2024-46652CRITICAL9.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
CVE-2024-9035HIGH7.3A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This af...
CVE-2024-9034HIGH7.3A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now