2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30564CRITICAL9.8An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary...
CVE-2024-30257MEDIUM5.91Panel is an open source Linux server operation and maintenance management panel. The password verification in the sourc...
CVE-2024-2796CRITICAL9.3A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1....
CVE-2024-29021CRITICAL9Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable...
CVE-2024-28189CRITICAL10Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file ...
CVE-2024-28185CRITICAL10Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s...
CVE-2024-27306MEDIUM6.1aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index page...
CVE-2024-3948CRITICAL9.8A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by th...
CVE-2024-32689MEDIUM4.3Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a th...
CVE-2024-32686MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migr...
CVE-2024-32602HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems Woo...
CVE-2024-32600CRITICAL9.6Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a throu...
CVE-2024-32553HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Supe...
CVE-2024-32552MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tagbox Taggbox all...
CVE-2024-32551HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro...
CVE-2024-32126MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navi...
CVE-2024-31229MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Si...
CVE-2024-32586MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munir Kamal Gutenb...
CVE-2024-32585MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Co...
CVE-2024-32584MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech Ter...
CVE-2024-32583MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team...
CVE-2024-32582HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Man...
CVE-2024-32581MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lenderd Mortgage C...
CVE-2024-32580MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid...
CVE-2024-32579MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaur...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now