2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29376MEDIUM6.4Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
CVE-2024-31666CRITICAL9.8An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon...
CVE-2024-28436MEDIUM6.1Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DA...
CVE-2024-28699HIGH7.8A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::cop...
CVE-2024-3645MEDIUM6.4The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-32368HIGH7.3Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta...
CVE-2024-27349CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f...
CVE-2024-27348CRITICAL9.8RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1...
CVE-2024-27347MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: ...
CVE-2024-4026MEDIUM4.6Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store ...
CVE-2024-29661CRITICAL9.8A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CVE-2024-28717MEDIUM4.9An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.
CVE-2024-22856MEDIUM5.4A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth...
CVE-2024-22815MEDIUM5.3An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cau...
CVE-2024-22813MEDIUM4.4An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP addres...
CVE-2024-22811HIGH8.2An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b...
CVE-2024-22809MEDIUM6.5Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code...
CVE-2024-22808HIGH7.5An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b...
CVE-2024-22807MEDIUM6.5An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the fl...
CVE-2024-32691MEDIUM5.3Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Produ...
CVE-2024-32688MEDIUM6.5Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.
CVE-2024-32687MEDIUM4.3Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Fr...
CVE-2024-32684HIGH7.5Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through ...
CVE-2024-32682HIGH8.8Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad...
CVE-2024-32681HIGH8.8Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now