2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36683HIGH7.3SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho...
CVE-2024-36681CRITICAL9.8SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker...
CVE-2024-34992HIGH8.8SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4....
CVE-2024-34988CRITICAL9.8SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=...
CVE-2024-22168MEDIUM5.9A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found ...
CVE-2024-6293HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6292HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6291HIGH8.8Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit ...
CVE-2024-6290HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co...
CVE-2024-36682HIGH7.5In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all ema...
CVE-2024-34991HIGH7.5In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credi...
CVE-2024-33898CRITICAL9.8Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An ...
CVE-2024-38903MEDIUM4.1H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
CVE-2024-38902CRITICAL9.8H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack...
CVE-2024-38897MEDIUM5.3WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
CVE-2024-38896MEDIUM5.3WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
CVE-2024-38895MEDIUM5.3WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
CVE-2024-38894MEDIUM5.3WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
CVE-2024-38892MEDIUM6.5An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh compon...
CVE-2024-37759CRITICAL9.8DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi...
CVE-2024-37681MEDIUM6.5An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote atta...
CVE-2024-37678MEDIUM5.3Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows...
CVE-2024-34313CRITICAL9.8An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu...
CVE-2024-34312MEDIUM6.1Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2024-37732MEDIUM6.1Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a craft...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now