2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54380HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies...
CVE-2024-54379HIGH8.8Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects...
CVE-2024-54378HIGH8.8Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue ...
CVE-2024-54375HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Woolook woolook al...
CVE-2024-54374HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allo...
CVE-2024-54373HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmi...
CVE-2024-54365HIGH8.8Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege E...
CVE-2024-54364HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spartac Feedpress ...
CVE-2024-54359HIGH8.2Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Co...
CVE-2024-54358HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D ...
CVE-2024-54355HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.T...
CVE-2024-54353HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-...
CVE-2024-54352HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects So...
CVE-2024-54332HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allow...
CVE-2024-54331HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affe...
CVE-2024-12668HIGH8.2Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp...
CVE-2024-10972HIGH7.3Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with...
CVE-2024-12478HIGH8.8A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the ...
CVE-2024-12646HIGH8.1The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local...
CVE-2024-12644HIGH7.1The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser...
CVE-2024-12643HIGH8.1The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ...
CVE-2024-12642HIGH8.1TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca...
CVE-2024-56086HIGH7.1An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are...
CVE-2024-56084HIGH7.1An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea...
CVE-2024-53376HIGH8.8CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now