2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7540LOW3.3oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac...
CVE-2024-7539HIGH7.8oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execut...
CVE-2024-7538HIGH7.8oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attacker...
CVE-2024-7537MEDIUM5.5oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attacker...
CVE-2024-7494CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1....
CVE-2024-42352HIGH7.5Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` pro...
CVE-2024-41811LOW3.9ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain c...
CVE-2024-34344HIGH8.8Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insu...
CVE-2024-34343MEDIUM6.1Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo...
CVE-2024-23657HIGH8.8Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools i...
CVE-2024-6915CRITICAL9.3JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to...
CVE-2024-42350LOW3Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforc...
CVE-2024-41960MEDIUM4.8mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja...
CVE-2024-41959MEDIUM6.1mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja...
CVE-2024-41958HIGH7.2mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the ...
CVE-2024-41820MEDIUM6Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has ...
CVE-2024-41816MEDIUM5.4Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scriptin...
CVE-2024-6361MEDIUM5.4Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all v...
CVE-2024-42010HIGH7.5mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) to...
CVE-2024-42009CRITICAL9.3A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea...
CVE-2024-42008CRITICAL9.3A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7...
CVE-2024-41381MEDIUM6.1microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\ad...
CVE-2024-41380MEDIUM6.1microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_ta...
CVE-2024-41376HIGH8.8dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
CVE-2024-41200MEDIUM5.5A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now