2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30564 | CRITICAL | 9.8 | 1.2% | Apr 18, 2024 | An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary... |
| CVE-2024-30257 | MEDIUM | 5.9 | 0.4% | Apr 18, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. The password verification in the sourc... |
| CVE-2024-2796 | CRITICAL | 9.3 | 0.4% | Apr 18, 2024 | A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.... |
| CVE-2024-29021 | CRITICAL | 9 | 20.2% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable... |
| CVE-2024-28189 | CRITICAL | 10 | 7.2% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file ... |
| CVE-2024-28185 | CRITICAL | 10 | 7.1% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s... |
| CVE-2024-27306 | MEDIUM | 6.1 | 0.7% | Apr 18, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index page... |
| CVE-2024-3948 | CRITICAL | 9.8 | 0.9% | Apr 18, 2024 | A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-32689 | MEDIUM | 4.3 | 0.3% | Apr 18, 2024 | Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a th... |
| CVE-2024-32686 | MEDIUM | 5.3 | 0.4% | Apr 18, 2024 | Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migr... |
| CVE-2024-32602 | HIGH | 7.2 | 0.5% | Apr 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems Woo... |
| CVE-2024-32600 | CRITICAL | 9.6 | 0.5% | Apr 18, 2024 | Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a throu... |
| CVE-2024-32553 | HIGH | 7.1 | 0.5% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Supe... |
| CVE-2024-32552 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tagbox Taggbox all... |
| CVE-2024-32551 | HIGH | 7.6 | 0.5% | Apr 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro... |
| CVE-2024-32126 | MEDIUM | 5.9 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navi... |
| CVE-2024-31229 | MEDIUM | 5.5 | 0.3% | Apr 18, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Si... |
| CVE-2024-32586 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munir Kamal Gutenb... |
| CVE-2024-32585 | MEDIUM | 5.9 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Co... |
| CVE-2024-32584 | MEDIUM | 4.8 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech Ter... |
| CVE-2024-32583 | MEDIUM | 6.1 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team... |
| CVE-2024-32582 | HIGH | 7.1 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Man... |
| CVE-2024-32581 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lenderd Mortgage C... |
| CVE-2024-32580 | MEDIUM | 5.4 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid... |
| CVE-2024-32579 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaur... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now