2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7330MEDIUM6.3A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the functio...
CVE-2024-7329CRITICAL9.8A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the fil...
CVE-2024-7328MEDIUM5.3A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown pr...
CVE-2024-38182CRITICAL9.8Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVE-2024-7327HIGH8.8A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataActi...
CVE-2024-41262HIGH7.4mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly all...
CVE-2024-7326HIGH7.8A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknow...
CVE-2024-4187MEDIUM5.4Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerab...
CVE-2024-41258MEDIUM5.3An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, ...
CVE-2024-41256MEDIUM5.9Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certi...
CVE-2024-41255HIGH7.5filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attack...
CVE-2024-41254MEDIUM5.3An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verificati...
CVE-2024-41253HIGH7.1goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-m...
CVE-2024-40465HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function i...
CVE-2024-40464HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located i...
CVE-2024-7325HIGH7.8A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is som...
CVE-2024-41955MEDIUM5.4Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo...
CVE-2024-41954HIGH7.8FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account cred...
CVE-2024-41951MEDIUM4.4Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The...
CVE-2024-41660CRITICAL9.8slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing th...
CVE-2024-41630HIGH7.6Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary cod...
CVE-2024-41108MEDIUM5.9FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improp...
CVE-2024-40645HIGH8.8FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows a...
CVE-2024-7324HIGH8.5A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this ...
CVE-2024-23444HIGH7.5It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now