2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40394CRITICAL9.8Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnera...
CVE-2024-40393CRITICAL9.8Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerabilit...
CVE-2024-40392CRITICAL9.8SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 ...
CVE-2024-40130CRITICAL9.8open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.
CVE-2024-40129CRITICAL9.8Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.
CVE-2024-39036MEDIUM6.5SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
CVE-2024-40425CRITICAL9.8File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a ...
CVE-2024-39908MEDIUM4.3 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that ha...
CVE-2024-39700CRITICAL9.8JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this templat...
CVE-2024-33181HIGH8.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parame...
CVE-2024-6326MEDIUM5.5An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali...
CVE-2024-6325MEDIUM6.5The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e...
CVE-2024-6089HIGH7.5An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent...
CVE-2024-40626MEDIUM5.4Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering pr...
CVE-2024-3232MEDIUM6.8A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with admini...
CVE-2024-40322HIGH8.8An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
CVE-2024-35338CRITICAL9.8Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
CVE-2024-33182CRITICAL9.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet...
CVE-2024-33180CRITICAL9.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet...
CVE-2024-22442CRITICAL9.8The vulnerability could be remotely exploited to bypass authentication.
CVE-2024-6655HIGH7A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK ap...
CVE-2024-32861HIGH7.8Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission...
CVE-2024-6435HIGH8.8A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privi...
CVE-2024-6621MEDIUM4.3The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth...
CVE-2024-6457HIGH7.5The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now