2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1755HIGH8.8The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-1754MEDIUM4.7The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-1746MEDIUM5.4The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allo...
CVE-2024-1712MEDIUM4.7The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-1660MEDIUM4.8The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-1310MEDIUM4.9The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking produ...
CVE-2024-1307MEDIUM6.5The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow us...
CVE-2024-1306MEDIUM5.4The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to...
CVE-2024-1204MEDIUM4.3The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitr...
CVE-2024-0902MEDIUM4.8The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could...
CVE-2024-0399HIGH8.1The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before ...
CVE-2024-3778HIGH7.2The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attacker...
CVE-2024-3777CRITICAL9.8The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset...
CVE-2024-3776MEDIUM6.1The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated re...
CVE-2024-3775HIGH7.5aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user inpu...
CVE-2024-3769CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un...
CVE-2024-3768CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue...
CVE-2024-3767HIGH8.8A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code ...
CVE-2024-1655HIGH8.8Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to...
CVE-2024-3774MEDIUM5.3aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction...
CVE-2024-3772HIGH7.5Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service vi...
CVE-2024-3766LOW2.4A vulnerability, which was classified as problematic, has been found in slowlyo OwlAdmin up to 3.5.7. Affected by this i...
CVE-2024-29844CRITICAL9.8Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p...
CVE-2024-29843HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29842HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now