2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37880HIGH7.5The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimizatio...
CVE-2024-5389HIGH8.1In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, ...
CVE-2024-4577CRITICAL9.8In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, ...
CVE-2024-37570HIGH8.8On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the use...
CVE-2024-37569HIGH8.8An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerab...
CVE-2024-2408MEDIUM5.9The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is ...
CVE-2024-5585HIGH8.8In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if...
CVE-2024-5458MEDIUM5.3In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering funct...
CVE-2024-37568HIGH7.5lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a ...
CVE-2024-35748MEDIUM5.3Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n...
CVE-2024-35662HIGH8.8Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD F...
CVE-2024-35661CRITICAL9.8Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: f...
CVE-2024-34802CRITICAL9.8Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – ...
CVE-2024-32081HIGH8.8Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Cu...
CVE-2024-31304HIGH8.8Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4...
CVE-2024-31284CRITICAL9.8Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8.
CVE-2024-31283CRITICAL9.8Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pic...
CVE-2024-31276CRITICAL9.8Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects P...
CVE-2024-31275CRITICAL9.8Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.
CVE-2024-32713HIGH8.8Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | ...
CVE-2024-32705HIGH8.8Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=...
CVE-2024-32704MEDIUM6.5Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=...
CVE-2024-32703HIGH8.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForm...
CVE-2024-32701HIGH8.8Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from ...
CVE-2024-31423HIGH8.8Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Hel...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now