2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29152HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, ...
CVE-2024-25095HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affec...
CVE-2024-36550HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohre...
CVE-2024-36549HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohre...
CVE-2024-36548HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
CVE-2024-36547HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mud...
CVE-2024-36400CRITICAL9.8nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using...
CVE-2024-35653MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi...
CVE-2024-35652MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolo...
CVE-2024-35651MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plug...
CVE-2024-35649MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Sa...
CVE-2024-32871HIGH7.5Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood t...
CVE-2024-29004MEDIUM4.3The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web c...
CVE-2024-28999HIGH7.5The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.
CVE-2024-28996HIGH7.5The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for t...
CVE-2024-0756MEDIUM5.4The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding i...
CVE-2024-35782MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Co...
CVE-2024-35700CRITICAL9.8Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a throug...
CVE-2024-35668MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsl...
CVE-2024-35666MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat ...
CVE-2024-35664MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPv...
CVE-2024-35655MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave brave-...
CVE-2024-35654MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps...
CVE-2024-35634MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce ...
CVE-2024-35629CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now