2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32955MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowpla...
CVE-2024-32951MEDIUM6.5Missing Authorization vulnerability in BloomPixel Max Addons Pro for Bricks.This issue affects Max Addons Pro for Bricks...
CVE-2024-32948CRITICAL9.1Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.
CVE-2024-32819MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Culqi.This issue affects Culqi: from n/a through 3.0.14.
CVE-2024-33531HIGH8.1cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc ...
CVE-2024-32051MEDIUM6.5Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is ...
CVE-2024-31406HIGH8.8Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-ad...
CVE-2024-3261MEDIUM4.8The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields befor...
CVE-2024-2972LOW3.8The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button ...
CVE-2024-2404MEDIUM5.4The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow l...
CVE-2024-2402MEDIUM5.4The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-1756MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, a...
CVE-2024-1743MEDIUM5.9The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before ou...
CVE-2024-28613CRITICAL9.8SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obta...
CVE-2024-4093HIGH8.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Subscription Website 1.0. Affected...
CVE-2024-4075MEDIUM6.1A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. T...
CVE-2024-4074MEDIUM6.1A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic...
CVE-2024-4073MEDIUM5.4A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problema...
CVE-2024-4072MEDIUM5.4A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as proble...
CVE-2024-4071HIGH8.8A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This ...
CVE-2024-4070HIGH7.5A vulnerability has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. ...
CVE-2024-4069HIGH7.5A vulnerability, which was classified as critical, was found in Kashipara Online Furniture Shopping Ecommerce Website 1....
CVE-2024-31616HIGH8.8An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(...
CVE-2024-30886MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execut...
CVE-2024-27537Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now