2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54135HIGH8.8ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are v...
CVE-2024-12254HIGH8.7Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa...
CVE-2024-54141HIGH7.5phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, p...
CVE-2024-11738HIGH7.5A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente...
CVE-2024-54216HIGH7.7Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForm...
CVE-2024-54209HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome ...
CVE-2024-54208HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block ...
CVE-2024-54205HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery...
CVE-2024-53825HIGH7.2Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Cont...
CVE-2024-53824HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-53821HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Pie Regis...
CVE-2024-53817HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Product La...
CVE-2024-53815HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoin...
CVE-2024-53812HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange ...
CVE-2024-53808HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms ne...
CVE-2024-53804HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb...
CVE-2024-53803HIGH8.8Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access...
CVE-2024-21571HIGH8.1Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables...
CVE-2024-10516HIGH8.1The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc...
CVE-2024-10776HIGH8.2Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att...
CVE-2024-10774HIGH7.3Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web...
CVE-2024-10772HIGH8.8Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high imp...
CVE-2024-10771HIGH8.8Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code...
CVE-2024-53907HIGH7.5An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an...
CVE-2024-53142HIGH7.8In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now