2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36315MEDIUM5.7Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten...
CVE-2024-54017MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-0391MEDIUM4.3The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker ...
CVE-2024-53326HIGH7.3LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(...
CVE-2024-51092CRITICAL9.1LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr...
CVE-2024-46508HIGH7.5yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting ...
CVE-2024-46507HIGH7.3A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor...
CVE-2024-45257HIGH7.3A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi...
CVE-2024-33724MEDIUM5.4SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
CVE-2024-33722MEDIUM6.3SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVE-2024-33288HIGH7.3Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the ...
CVE-2024-30167MEDIUM6.3/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm...
CVE-2024-27686HIGH7.5Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic...
CVE-2024-43384HIGH8A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor...
CVE-2024-30151HIGH8.3HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation...
CVE-2024-52911HIGH7.5Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is...
CVE-2024-13362MEDIUM6.1Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in v...
CVE-2024-13971HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-...
CVE-2024-39847HIGH7.5Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. Thi...
CVE-2024-54013HIGH8.8Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server co...
CVE-2024-54012MEDIUM5.3Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate i...
CVE-2024-54011MEDIUM6.5Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data sup...
CVE-2024-46636CRITICAL9.4NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v...
CVE-2024-58344MEDIUM6.4Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to ...
CVE-2024-7083LOW3.5The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow hi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now