2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25918HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This ...
CVE-2024-3253HIGH7.2A vulnerability classified as critical was found in SourceCodester Internship Portal Management System 1.0. This vulnera...
CVE-2024-3252CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This af...
CVE-2024-3251HIGH8.8A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been rated as critical. Af...
CVE-2024-0172HIGH7.8Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability....
CVE-2024-29734HIGH7.8Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely...
CVE-2024-28589MEDIUM6.7An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attac...
CVE-2024-28515CRITICAL9.8Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod...
CVE-2024-24506MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attacke...
CVE-2024-31008MEDIUM6.5An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive inf...
CVE-2024-30998CRITICAL9.8SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar...
CVE-2024-31011CRITICAL9.8Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path ...
CVE-2024-2322MEDIUM6.8The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, w...
CVE-2024-31013MEDIUM6.1Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via ...
CVE-2024-31012CRITICAL9.8An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obt...
CVE-2024-31010HIGH7.5SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID paramet...
CVE-2024-31009MEDIUM6.5SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter...
CVE-2024-2879HIGH7.5The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1...
CVE-2024-3227HIGH7.2A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects u...
CVE-2024-3162MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attri...
CVE-2024-30166CRITICAL9.1In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service...
CVE-2024-28836MEDIUM5.4An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall...
CVE-2024-28755MEDIUM6.5An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset...
CVE-2024-28219MEDIUM5.9In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVE-2024-26495MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now