2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47886 | HIGH | 7.2 | 0.9% | Mar 2, 2026 | Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a... |
| CVE-2024-10938 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ... |
| CVE-2024-48928 | HIGH | 7.5 | 0.3% | Feb 24, 2026 | Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec... |
| CVE-2024-56373 | HIGH | 8.4 | 1.1% | Feb 24, 2026 | DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb... |
| CVE-2024-1524 | HIGH | 8.1 | 0.3% | Feb 24, 2026 | When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ... |
| CVE-2024-58041 | CRITICAL | 9.1 | 0.4% | Feb 24, 2026 | Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl... |
| CVE-2024-56208 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM... |
| CVE-2024-54222 | MEDIUM | 4.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr... |
| CVE-2024-52387 | MEDIUM | 5.9 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste... |
| CVE-2024-51915 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo... |
| CVE-2024-50555 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2024-50452 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl... |
| CVE-2024-43228 | MEDIUM | 5.3 | 0.2% | Feb 20, 2026 | Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th... |
| CVE-2024-34438 | MEDIUM | 5.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a... |
| CVE-2024-43178 | HIGH | 7.5 | 0.1% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2024-55270 | HIGH | 8.8 | 0.3% | Feb 17, 2026 | phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata... |
| CVE-2024-55271 | LOW | 3.5 | 0.1% | Feb 17, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issu... |
| CVE-2024-31118 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure... |
| CVE-2024-34157 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2024-34154 | — | — | — | Feb 13, 2026 | Rejected reason: reserved but not needed |
| CVE-2024-21961 | MEDIUM | 6 | 0.3% | Feb 13, 2026 | Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces... |
| CVE-2024-36319 | MEDIUM | 6.3 | 0.1% | Feb 12, 2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr... |
| CVE-2024-50619 | HIGH | 8.8 | 0.2% | Feb 11, 2026 | Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es... |
| CVE-2024-50617 | HIGH | 7.5 | 0.2% | Feb 11, 2026 | Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to... |
| CVE-2024-50620 | HIGH | 8.8 | 0.3% | Feb 11, 2026 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now