2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34707MEDIUM4.8Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify ...
CVE-2024-34706CRITICAL9.8Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access toke...
CVE-2024-34704MEDIUM5.9era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DA...
CVE-2024-34701MEDIUM5.9CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered ...
CVE-2024-34699MEDIUM6.5GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on o...
CVE-2024-34698MEDIUM6.3FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototyp...
CVE-2024-34697MEDIUM6.1FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified...
CVE-2024-34695MEDIUM6.3WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" ...
CVE-2024-34559HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from ...
CVE-2024-34557MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or...
CVE-2024-34556MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner wit...
CVE-2024-34555CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: ...
CVE-2024-34550MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects D...
CVE-2024-34549MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects...
CVE-2024-34459HIGH7.5An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with...
CVE-2024-34445MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Add...
CVE-2024-34441MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventu...
CVE-2024-34440HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect...
CVE-2024-34439MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a ...
CVE-2024-34437MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder...
CVE-2024-34436MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Add...
CVE-2024-34433HIGH7.2Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: ...
CVE-2024-34432MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Bette...
CVE-2024-34431HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etr...
CVE-2024-34430MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Cu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now