2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34027HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_comp...
CVE-2024-33847MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on...
CVE-2024-33278CRITICAL9.8Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker...
CVE-2024-32936MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting...
CVE-2024-5862HIGH7.5Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication...
CVE-2024-4839LOW3.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms...
CVE-2024-3264MEDIUM5.3Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows S...
CVE-2024-37233MEDIUM4.3Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This is...
CVE-2024-37231CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Sal...
CVE-2024-37228CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affe...
CVE-2024-37111HIGH7.5Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from ...
CVE-2024-37109HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows ...
CVE-2024-37107HIGH8.8Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This is...
CVE-2024-37092HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin...
CVE-2024-37091HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Cons...
CVE-2024-37089CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin...
CVE-2024-36038MEDIUM6.3Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerabi...
CVE-2024-6160CRITICAL9.3SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session...
CVE-2024-29868CRITICAL9.1Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-regist...
CVE-2024-5683CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process ...
CVE-2024-4754MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM...
CVE-2024-36497CRITICAL9.1The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be use...
CVE-2024-36496HIGH7.5The configuration file is encrypted with a static key derived from a static five-character password which allows an att...
CVE-2024-36495HIGH7.7The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file syst...
CVE-2024-27136MEDIUM6.1XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now