2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51222MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag...
CVE-2024-13785MEDIUM5.6The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc...
CVE-2024-44722CRITICAL9.8SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
CVE-2024-32537HIGH7.1Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This...
CVE-2024-31119MEDIUM5.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl...
CVE-2024-42210MEDIUM5.4A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower.  Stored cros...
CVE-2024-14026HIGH7.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai...
CVE-2024-14025MEDIUM6.7An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ...
CVE-2024-14024MEDIUM6.7An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n...
CVE-2024-14027MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat...
CVE-2024-35644MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc...
CVE-2024-43035MEDIUM5.8Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V...
CVE-2024-57854CRITICAL9.1Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us...
CVE-2024-55027HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_...
CVE-2024-55026CRITICAL9.8An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers...
CVE-2024-55025MEDIUM6.5Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a...
CVE-2024-55024CRITICAL9.8An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v202310...
CVE-2024-55023MEDIUM5.3Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow...
CVE-2024-55022HIGH8.8Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerabi...
CVE-2024-55021HIGH7.5Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
CVE-2024-55020CRITICAL9.8A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS ...
CVE-2024-55019HIGH7.5Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310...
CVE-2024-43766MEDIUM6.5In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th...
CVE-2024-31328HIGH8.8In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from ...
CVE-2024-50337MEDIUM5.3Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now