2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43802MEDIUM4.5Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current positio...
CVE-2024-45265CRITICAL9.8A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe...
CVE-2024-42913CRITICAL9.8RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
CVE-2024-8174MEDIUM6.1A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vu...
CVE-2024-7401HIGH7.5Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token ...
CVE-2024-42792LOW3.5A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.ph...
CVE-2024-42790MEDIUM5.4A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Manage...
CVE-2024-41444CRITICAL9.8SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
CVE-2024-8173HIGH7.5A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unkn...
CVE-2024-8172MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. Th...
CVE-2024-8171CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability aff...
CVE-2024-8170CRITICAL9.8A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects a...
CVE-2024-44557CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
CVE-2024-44555CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
CVE-2024-44553CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
CVE-2024-44552CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
CVE-2024-44551CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
CVE-2024-44550CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
CVE-2024-44549CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
CVE-2024-43967MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digit...
CVE-2024-43319MEDIUM4.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue ...
CVE-2024-43289HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affect...
CVE-2024-43283HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest G...
CVE-2024-42818MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Config-Create function of fastapi-admin pro v0.1.4 allows attackers to...
CVE-2024-42816MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now