2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44913MEDIUM5.5An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a...
CVE-2024-42905CRITICAL9.8Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can b...
CVE-2024-41236HIGH7.2A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an...
CVE-2024-7745HIGH8.1In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra...
CVE-2024-7744MEDIUM6.5In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path...
CVE-2024-6053MEDIUM4.3Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamV...
CVE-2024-41565MEDIUM5.3JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in In...
CVE-2024-41564MEDIUM5.3EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in I...
CVE-2024-20478HIGH7.2A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco...
CVE-2024-20446HIGH8.6A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cau...
CVE-2024-20413MEDIUM6.7A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ...
CVE-2024-20411MEDIUM6.7A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ...
CVE-2024-20289MEDIUM4.4A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execu...
CVE-2024-20286HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-20285HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-20284HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...
CVE-2024-20279MEDIUM4.3A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (...
CVE-2024-42900MEDIUM6.1Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of th...
CVE-2024-42698MEDIUM5.3Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset...
CVE-2024-34198CRITICAL9.8TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI ha...
CVE-2024-8195MEDIUM5.3The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-7447MEDIUM5.3The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-6450MEDIUM6.1HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unaut...
CVE-2024-6449MEDIUM6.5HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote co...
CVE-2024-7269MEDIUM5.4Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now