2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39021MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?...
CVE-2024-39020MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?...
CVE-2024-39019MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?...
CVE-2024-34361HIGH8.8Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vul...
CVE-2024-39687HIGH7.2Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present...
CVE-2024-39321HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability ...
CVE-2024-39174MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute ar...
CVE-2024-37903HIGH8.2Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and ...
CVE-2024-39178MEDIUM5.4MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump...
CVE-2024-39150MEDIUM5.9vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.
CVE-2024-37767HIGH7.5Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information v...
CVE-2024-27717MEDIUM6.5Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a rem...
CVE-2024-27716MEDIUM5.4Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary...
CVE-2024-27715HIGH8.2An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27713HIGH8.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27712CRITICAL9.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27711HIGH8.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27710CRITICAL9.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27709CRITICAL9.8SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the sear...
CVE-2024-39210HIGH7.5Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page par...
CVE-2024-37769HIGH8.8Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a cra...
CVE-2024-37768CRITICAL9.114Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
CVE-2024-29319CRITICAL9.8Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. ...
CVE-2024-29318MEDIUM5.4Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file wi...
CVE-2024-23998CRITICAL9.6goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now