2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43802 | MEDIUM | 4.5 | 0.3% | Aug 26, 2024 | Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current positio... |
| CVE-2024-45265 | CRITICAL | 9.8 | 1.0% | Aug 26, 2024 | A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe... |
| CVE-2024-42913 | CRITICAL | 9.8 | 0.4% | Aug 26, 2024 | RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1. |
| CVE-2024-8174 | MEDIUM | 6.1 | 0.5% | Aug 26, 2024 | A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vu... |
| CVE-2024-7401 | HIGH | 7.5 | 0.8% | Aug 26, 2024 | Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token ... |
| CVE-2024-42792 | LOW | 3.5 | 0.2% | Aug 26, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.ph... |
| CVE-2024-42790 | MEDIUM | 5.4 | 0.5% | Aug 26, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Manage... |
| CVE-2024-41444 | CRITICAL | 9.8 | 0.5% | Aug 26, 2024 | SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so. |
| CVE-2024-8173 | HIGH | 7.5 | 0.7% | Aug 26, 2024 | A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unkn... |
| CVE-2024-8172 | MEDIUM | 6.1 | 0.4% | Aug 26, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. Th... |
| CVE-2024-8171 | CRITICAL | 9.8 | 0.5% | Aug 26, 2024 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability aff... |
| CVE-2024-8170 | CRITICAL | 9.8 | 0.7% | Aug 26, 2024 | A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects a... |
| CVE-2024-44557 | CRITICAL | 9.8 | 0.6% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo. |
| CVE-2024-44555 | CRITICAL | 9.8 | 0.7% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. |
| CVE-2024-44553 | CRITICAL | 9.8 | 0.6% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. |
| CVE-2024-44552 | CRITICAL | 9.8 | 0.4% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. |
| CVE-2024-44551 | CRITICAL | 9.8 | 0.6% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv. |
| CVE-2024-44550 | CRITICAL | 9.8 | 0.6% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv. |
| CVE-2024-44549 | CRITICAL | 9.8 | 0.4% | Aug 26, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv. |
| CVE-2024-43967 | MEDIUM | 4.8 | 0.3% | Aug 26, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digit... |
| CVE-2024-43319 | MEDIUM | 4.3 | 0.4% | Aug 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue ... |
| CVE-2024-43289 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affect... |
| CVE-2024-43283 | HIGH | 7.5 | 1.1% | Aug 26, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest G... |
| CVE-2024-42818 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to... |
| CVE-2024-42816 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now