2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6645MEDIUM6.3A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected b...
CVE-2024-6644MEDIUM6.3A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function ge...
CVE-2024-5217CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl...
CVE-2024-5178MEDIUM6.9ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Ut...
CVE-2024-4879CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo...
CVE-2024-3325HIGH7.2Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.
CVE-2024-40417MEDIUM6.5A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file...
CVE-2024-40412MEDIUM6.8Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.
CVE-2024-20456MEDIUM6.7A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv...
CVE-2024-40336MEDIUM6.1idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.'
CVE-2024-40332HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php...
CVE-2024-40331HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?...
CVE-2024-6642Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2024-40334HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?...
CVE-2024-40333HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-40329HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud...
CVE-2024-40328MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.ph...
CVE-2024-28828HIGH8.8Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click com...
CVE-2024-28827HIGH7.8Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <=...
CVE-2024-3799HIGH8.7Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec...
CVE-2024-3798HIGH8.7Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project...
CVE-2024-6556MEDIUM5.3The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclo...
CVE-2024-6422CRITICAL9.8An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
CVE-2024-6421HIGH7.5An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic...
CVE-2024-5664MEDIUM5.4The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now