2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41684MEDIUM5.3This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies assoc...
CVE-2024-35296HIGH8.2Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This...
CVE-2024-35161HIGH7.5Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for reques...
CVE-2024-25090MEDIUM5.4Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name...
CVE-2024-6490MEDIUM6.5During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an un...
CVE-2024-40897MEDIUM6.7Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricke...
CVE-2024-7120CRITICAL9.8A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. Th...
CVE-2024-7119HIGH8.8A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System u...
CVE-2024-7118HIGH8.8A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Af...
CVE-2024-7117HIGH8.8A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 2023091...
CVE-2024-7116HIGH8.8A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as crit...
CVE-2024-7115HIGH8.8A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as c...
CVE-2024-7114HIGH8.8A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part...
CVE-2024-4447CRITICAL9.9In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting...
CVE-2024-41473CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/Wr...
CVE-2024-41468CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform...
CVE-2024-3938MEDIUM6.1The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patc...
CVE-2024-38103MEDIUM5.9Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-24623HIGH8.8Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticat...
CVE-2024-24622HIGH8.8Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker ca...
CVE-2024-24621CRITICAL9.8Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, ano...
CVE-2024-7106HIGH8.8A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown fu...
CVE-2024-7105HIGH8.8A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown...
CVE-2024-41809MEDIUM6.1OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve...
CVE-2024-6558MEDIUM6.1HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanita...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now