2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51222 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag... |
| CVE-2024-13785 | MEDIUM | 5.6 | 0.3% | Mar 21, 2026 | The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc... |
| CVE-2024-44722 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. |
| CVE-2024-32537 | HIGH | 7.1 | 0.1% | Mar 20, 2026 | Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This... |
| CVE-2024-31119 | MEDIUM | 5.9 | 0.2% | Mar 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl... |
| CVE-2024-42210 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cros... |
| CVE-2024-14026 | HIGH | 7.8 | 0.6% | Mar 11, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai... |
| CVE-2024-14025 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ... |
| CVE-2024-14024 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n... |
| CVE-2024-14027 | MEDIUM | 5.5 | 0.3% | Mar 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat... |
| CVE-2024-35644 | MEDIUM | 5.9 | 0.2% | Mar 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc... |
| CVE-2024-43035 | MEDIUM | 5.8 | 2.4% | Mar 5, 2026 | Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V... |
| CVE-2024-57854 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us... |
| CVE-2024-55027 | HIGH | 7.5 | 0.2% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_... |
| CVE-2024-55026 | CRITICAL | 9.8 | 0.3% | Mar 3, 2026 | An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers... |
| CVE-2024-55025 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a... |
| CVE-2024-55024 | CRITICAL | 9.8 | 0.4% | Mar 3, 2026 | An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v202310... |
| CVE-2024-55023 | MEDIUM | 5.3 | 0.2% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow... |
| CVE-2024-55022 | HIGH | 8.8 | 1.3% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerabi... |
| CVE-2024-55021 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. |
| CVE-2024-55020 | CRITICAL | 9.8 | 1.7% | Mar 3, 2026 | A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS ... |
| CVE-2024-55019 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310... |
| CVE-2024-43766 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th... |
| CVE-2024-31328 | HIGH | 8.8 | 0.1% | Mar 2, 2026 | In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from ... |
| CVE-2024-50337 | MEDIUM | 5.3 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now