2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45752HIGH7.3logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u...
CVE-2024-7785CRITICAL9.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Softwar...
CVE-2024-46394HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
CVE-2024-46382HIGH7.5A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ...
CVE-2024-8986CRITICAL9.1The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI f...
CVE-2024-8354MEDIUM5.5A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ...
CVE-2024-45770MEDIUM4.4A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ...
CVE-2024-45769MEDIUM5.5A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to...
CVE-2024-47089MEDIUM6.5This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ...
CVE-2024-47088CRITICAL9.8This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attemp...
CVE-2024-47087MEDIUM6.5This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ...
CVE-2024-47086MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ...
CVE-2024-47085MEDIUM6.5This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic...
CVE-2024-46946CRITICAL9.8langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbit...
CVE-2024-8850MEDIUM6.1The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ...
CVE-2024-8364MEDIUM5.4The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre...
CVE-2024-7254HIGH7.5Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO...
CVE-2024-47059MEDIUM4.3When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa...
CVE-2024-37406HIGH7.5In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w...
CVE-2024-47058MEDIUM4.8With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use...
CVE-2024-47050MEDIUM6.1Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl...
CVE-2024-46377CRITICAL9.8Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function ...
CVE-2024-46376CRITICAL9.8Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function...
CVE-2024-46375CRITICAL9.8Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the ...
CVE-2024-46374CRITICAL9.8Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now