2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5013HIGH7.5In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. ...
CVE-2024-5012HIGH8.6In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Cred...
CVE-2024-38516HIGH8.8ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from envi...
CVE-2024-37855HIGH8.4An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote a...
CVE-2024-37843CRITICAL9.8Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CVE-2024-35526MEDIUM5.9An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in t...
CVE-2024-34400MEDIUM6.1An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layo...
CVE-2024-21741CRITICAL9.8GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
CVE-2024-21740HIGH7.4Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
CVE-2024-21739MEDIUM5.3Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control.
CVE-2024-6206HIGH7.5A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code i...
CVE-2024-5276CRITICAL9.1A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely imp...
CVE-2024-5011HIGH7.5In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A speciall...
CVE-2024-5010HIGH7.5In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specia...
CVE-2024-5009HIGH8.4In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.Instal...
CVE-2024-5008HIGH8.8In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitr...
CVE-2024-4885CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...
CVE-2024-4884CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...
CVE-2024-4883CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This v...
CVE-2024-4498HIGH7.7A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affectin...
CVE-2024-37894MEDIUM6.3Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when ass...
CVE-2024-37167MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see b...
CVE-2024-37820MEDIUM5.4A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expres...
CVE-2024-36819MEDIUM5.4MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to inse...
CVE-2024-6308CRITICAL9.8A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now