2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45052MEDIUM5.3Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulne...
CVE-2024-45050HIGH7.1Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messag...
CVE-2024-44859HIGH8Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
CVE-2024-44821MEDIUM5.3ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does ...
CVE-2024-44818MEDIUM5.4Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v...
CVE-2024-44817HIGH8.8SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the ...
CVE-2024-44808CRITICAL9.8An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.
CVE-2024-43405HIGH7.8Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2,...
CVE-2024-43402HIGH8.8Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments ...
CVE-2024-8418HIGH7.5A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP ...
CVE-2024-8411MEDIUM4.3A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int...
CVE-2024-8410HIGH7.5A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown...
CVE-2024-8409HIGH7.5A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part ...
CVE-2024-7078CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics...
CVE-2024-7077MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics...
CVE-2024-7076CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics...
CVE-2024-45506HIGH7.5HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2...
CVE-2024-44820MEDIUM6.1A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at...
CVE-2024-44819MEDIUM6.1Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v...
CVE-2024-8408CRITICAL9.8A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the functio...
CVE-2024-8407MEDIUM5.4A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p...
CVE-2024-7923CRITICAL9.8An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22....
CVE-2024-7012CRITICAL9.8An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to...
CVE-2024-7834HIGH7.8A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-...
CVE-2024-44400CRITICAL9.8A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now