2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37654MEDIUM6.1An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD,...
CVE-2024-36532CRITICAL10Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the...
CVE-2024-34989CRITICAL9.8In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injec...
CVE-2024-34452MEDIUM6.1CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.
CVE-2024-6241CRITICAL9.8A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function get...
CVE-2024-37675MEDIUM5.4Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute...
CVE-2024-37673MEDIUM5.4Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute...
CVE-2024-37672MEDIUM5.4Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute...
CVE-2024-37671MEDIUM5.4Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute...
CVE-2024-35537HIGH7.5TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair...
CVE-2024-37790Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-35781MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allo...
CVE-2024-35778HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE P...
CVE-2024-35767HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This is...
CVE-2024-6240CRITICAL10Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. A...
CVE-2024-6239HIGH7.5A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. B...
CVE-2024-37230HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: fr...
CVE-2024-37227HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a throug...
CVE-2024-37212HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a throug...
CVE-2024-37198HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: f...
CVE-2024-37118HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automato...
CVE-2024-5059HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.T...
CVE-2024-35776HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpi...
CVE-2024-35772HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7...
CVE-2024-35771HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a throu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now