2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33893MEDIUM6.1Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displayin...
CVE-2024-33892HIGH7.5Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s...
CVE-2024-7314CRITICAL9.8anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can app...
CVE-2024-41519MEDIUM5.4Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltunge...
CVE-2024-41518HIGH7.5An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allow...
CVE-2024-41517MEDIUM5.3An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2....
CVE-2024-41310HIGH7.5AndServer 2.1.12 is vulnerable to Directory Traversal.
CVE-2024-7029CRITICAL9.8Commands can be injected over the network and executed without authentication.
CVE-2024-41127CRITICAL9.6Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution throu...
CVE-2024-38890HIGH8.4An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later version...
CVE-2024-7323MEDIUM6.5Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately fi...
CVE-2024-7204MEDIUM6.1Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into...
CVE-2024-6704MEDIUM6.1The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.2...
CVE-2024-40723MEDIUM4.3The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the ...
CVE-2024-40722MEDIUM4.3The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate th...
CVE-2024-40721HIGH8.8The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-...
CVE-2024-40720HIGH8.8The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-...
CVE-2024-38879CRITICAL9.8A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A...
CVE-2024-38878MEDIUM6.5A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A...
CVE-2024-38877HIGH8.8A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont...
CVE-2024-38876HIGH7.8A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont...
CVE-2024-4643MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-40719MEDIUM6.5The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is ins...
CVE-2024-36268CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InL...
CVE-2024-27182MEDIUM4.9In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator accou...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now