2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41710HIGH7.2A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, ...
CVE-2024-40893MEDIUM6.8Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions...
CVE-2024-40892HIGH7.1A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a phys...
CVE-2024-42545CRITICAL9.8TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg functio...
CVE-2024-42543CRITICAL9.8TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth f...
CVE-2024-7700MEDIUM6.5A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packag...
CVE-2024-42627HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3...
CVE-2024-42626HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.
CVE-2024-42625HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add
CVE-2024-42624HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.
CVE-2024-42623HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1
CVE-2024-42474MEDIUM6.5Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a s...
CVE-2024-41651HIGH8.1An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func...
CVE-2024-41475HIGH8.8Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
CVE-2024-40500HIGH8.6Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute ar...
CVE-2024-42632HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.
CVE-2024-42631HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.
CVE-2024-42630HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-42629HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
CVE-2024-42628HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.
CVE-2024-42489HIGH8.8Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the...
CVE-2024-42485HIGH7.5Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` all...
CVE-2024-42482MEDIUM6.5fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in...
CVE-2024-42481HIGH7.5Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skypo...
CVE-2024-42480CRITICAL9.9Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now