2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2358CRITICAL9.8A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute ar...
CVE-2024-20793MEDIUM5.5Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis...
CVE-2024-20792HIGH7.8Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitr...
CVE-2024-20791HIGH7.8Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted...
CVE-2024-4966CRITICAL9.8A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknow...
CVE-2024-4965CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical....
CVE-2024-4964CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as crit...
CVE-2024-4546MEDIUM6.4The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_...
CVE-2024-4478MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Gro...
CVE-2024-4963CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R0...
CVE-2024-4962CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 ...
CVE-2024-4844HIGH7.5Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update...
CVE-2024-4961CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Aff...
CVE-2024-4960CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C...
CVE-2024-4946HIGH8.8A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. ...
CVE-2024-4843MEDIUM4.3ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow...
CVE-2024-4635MEDIUM6.4The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ fu...
CVE-2024-4318MEDIUM6.5The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions...
CVE-2024-4279MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2024-3644MEDIUM4.8The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-3643HIGH8.8The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attacke...
CVE-2024-3642MEDIUM6.9The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow a...
CVE-2024-3641MEDIUM6.1The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauth...
CVE-2024-4945CRITICAL9.8A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. A...
CVE-2024-4933CRITICAL9.8A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now