2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36014MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer derefer...
CVE-2024-4419MEDIUM4The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2024-3937MEDIUM4.8The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could al...
CVE-2024-3921MEDIUM4.8The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-3050CRITICAL9.1The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin...
CVE-2024-4611HIGH8.1The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_valu...
CVE-2024-21512HIGH8.2Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitizatio...
CVE-2024-0434MEDIUM5.3The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthoriz...
CVE-2024-5204HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1...
CVE-2024-5150CRITICAL9.8The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including...
CVE-2024-5437MEDIUM6.1A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Aff...
CVE-2024-36112MEDIUM6.5Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group rec...
CVE-2024-23580MEDIUM6.5HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an at...
CVE-2024-23579MEDIUM6.5HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker ...
CVE-2024-35548MEDIUM5.4A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio...
CVE-2024-35511MEDIUM4.7phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/i...
CVE-2024-35240MEDIUM5.4Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scri...
CVE-2024-35239MEDIUM5.4Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access...
CVE-2024-35226HIGH7.3Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In a...
CVE-2024-22641HIGH7.5TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG...
CVE-2024-35583MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-35582MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-35581MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu...
CVE-2024-35510CRITICAL9.8An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute ...
CVE-2024-28061MEDIUM6.3An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data st...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now