2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46373HIGH8.8Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
CVE-2024-46372MEDIUM6.1DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement manageme...
CVE-2024-40568CRITICAL9.8Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote a...
CVE-2024-44589HIGH8.8Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta...
CVE-2024-43025MEDIUM6.1An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and...
CVE-2024-43024MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to...
CVE-2024-39339HIGH7.5A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c...
CVE-2024-8287HIGH7.5Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the...
CVE-2024-34057HIGH7.5Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re...
CVE-2024-46989MEDIUM5.3spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom...
CVE-2024-46987HIGH7.7Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability ...
CVE-2024-46986CRITICAL9.9Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnera...
CVE-2024-46979MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2024-46978MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible f...
CVE-2024-46959MEDIUM6.5runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows ac...
CVE-2024-45601HIGH7.5Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi...
CVE-2024-45523CRITICAL9.1An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5...
CVE-2024-34399CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker ...
CVE-2024-46990MEDIUM5Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca...
CVE-2024-45813MEDIUM5.3find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route ...
CVE-2024-45298MEDIUM4.3Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the pass...
CVE-2024-46086HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-6878CRITICAL9.2Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common...
CVE-2024-6877MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa...
CVE-2024-5960CRITICAL9.8Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This iss...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now