2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47886HIGH7.2Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a...
CVE-2024-10938MEDIUM6.5The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ...
CVE-2024-48928HIGH7.5Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec...
CVE-2024-56373HIGH8.4DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb...
CVE-2024-1524HIGH8.1When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk ...
CVE-2024-58041CRITICAL9.1Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl...
CVE-2024-56208MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM...
CVE-2024-54222MEDIUM4.3Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr...
CVE-2024-52387MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2024-51915MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo...
CVE-2024-50555MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-50452MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl...
CVE-2024-43228MEDIUM5.3Missing Authorization vulnerability in SecuPress SecuPress Free secupress.This issue affects SecuPress Free: from n/a th...
CVE-2024-34438MEDIUM5.3Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a...
CVE-2024-43178HIGH7.5IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2024-55270HIGH8.8phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata...
CVE-2024-55271LOW3.5A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issu...
CVE-2024-31118MEDIUM6.5Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configure...
CVE-2024-34157Rejected reason: reserved but not needed
CVE-2024-34154Rejected reason: reserved but not needed
CVE-2024-21961MEDIUM6Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with acces...
CVE-2024-36319MEDIUM6.3Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously cr...
CVE-2024-50619HIGH8.8Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es...
CVE-2024-50617HIGH7.5Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to...
CVE-2024-50620HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now