2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41354HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
CVE-2024-41353HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
CVE-2024-27358LOW3.3An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security thro...
CVE-2024-27357MEDIUM5.8An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through...
CVE-2024-26520CRITICAL9.8An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 a...
CVE-2024-24257HIGH7.5An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen...
CVE-2024-7050HIGH8.3Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa...
CVE-2024-41807Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2023-4759. Reason: This record is a reservati...
CVE-2024-41357HIGH7.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
CVE-2024-41356MEDIUM4.7phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
CVE-2024-41355MEDIUM6.5phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
CVE-2024-41805MEDIUM6.1Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior t...
CVE-2024-41670HIGH7.5In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ...
CVE-2024-7128MEDIUM5.3A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWit...
CVE-2024-6922MEDIUM6.9Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attac...
CVE-2024-40689CRITICAL9.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2024-41692HIGH8.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte...
CVE-2024-7062HIGH7.8Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged...
CVE-2024-41691MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within th...
CVE-2024-41690MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credenti...
CVE-2024-41689MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials withi...
CVE-2024-41688MEDIUM4.6This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passw...
CVE-2024-41687HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ...
CVE-2024-41686LOW3.3This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A l...
CVE-2024-41685HIGH7.5This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now