2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41119CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41118CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41117CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41116CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41115CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41114CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-4786LOW2.8An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application...
CVE-2024-41113CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-41112CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...
CVE-2024-40117CRITICAL9.8Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrat...
CVE-2024-40116HIGH8.1An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the expo...
CVE-2024-38512HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38511HIGH7.2A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut...
CVE-2024-38510HIGH7.2A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe...
CVE-2024-38509HIGH7.2A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv...
CVE-2024-38508HIGH7.2A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t...
CVE-2024-42007MEDIUM5.8SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.
CVE-2024-39304HIGH8.8ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au...
CVE-2024-38872HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-38871HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i...
CVE-2024-41813HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ...
CVE-2024-41812HIGH7.5txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ...
CVE-2024-41375MEDIUM6.1ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
CVE-2024-41374MEDIUM6.1ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
CVE-2024-41373MEDIUM6.3ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now