2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39906HIGH8.3A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app...
CVE-2024-39123MEDIUM5.4In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due...
CVE-2024-40400HIGH8.8An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr...
CVE-2024-41600HIGH7.5Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive...
CVE-2024-41603CRITICAL9.6Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
CVE-2024-41602HIGH8.8Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privilege...
CVE-2024-41601HIGH7.5Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive informatio...
CVE-2024-41492HIGH7.5A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-41281HIGH8.8Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
CVE-2024-29080MEDIUM6.5Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En...
CVE-2024-24970MEDIUM6.5Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En...
CVE-2024-6908MEDIUM6Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin...
CVE-2024-6895MEDIUM6.1Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compro...
CVE-2024-39963HIGH8AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01...
CVE-2024-39962CRITICAL9.8D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (...
CVE-2024-27489HIGH7.5An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
CVE-2024-0006MEDIUM5.4Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs t...
CVE-2024-37066HIGH8.8A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to ...
CVE-2024-6916MEDIUM5.5A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a ...
CVE-2024-5977MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Refer...
CVE-2024-41107HIGH8.1The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh...
CVE-2024-6907MEDIUM5.4A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte...
CVE-2024-6906HIGH8.8A vulnerability was found in SourceCodester Record Management System 1.0 and classified as critical. This issue affects ...
CVE-2024-6905HIGH8.8A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as critical. This vulnerabi...
CVE-2024-6904HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Record Management System 1.0. This affect...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now