2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4870HIGH7.2The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,...
CVE-2024-4552CRITICAL9.8The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
CVE-2024-29976MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyx...
CVE-2024-29975MEDIUM6.7** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel N...
CVE-2024-29974CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA...
CVE-2024-29973CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar...
CVE-2024-29972CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326...
CVE-2024-36782CRITICAL9.8TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic...
CVE-2024-36783CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N...
CVE-2024-34987CRITICAL9.1A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2...
CVE-2024-34051MEDIUM4.6A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0....
CVE-2024-31682CRITICAL9.8Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attac...
CVE-2024-5388Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5387Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5214Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-31684LOW3.5Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows a...
CVE-2024-4332CRITICAL9.3An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (T...
CVE-2024-37019CRITICAL9.8Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
CVE-2024-4540HIGH7.5A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to ...
CVE-2024-36674MEDIUM6.1LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.
CVE-2024-32983HIGH7.5Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO...
CVE-2024-36128HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numer...
CVE-2024-36127HIGH7.5apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l...
CVE-2024-36124MEDIUM5.3iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bo...
CVE-2024-36123MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now