2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-30511MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issu...
CVE-2024-30492MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export ...
CVE-2024-30482HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Re...
CVE-2024-30477CRITICAL9.8Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for Woo...
CVE-2024-30469MEDIUM5.3Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce:...
CVE-2024-30247CRITICAL9.8NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command i...
CVE-2024-30246HIGH7.1Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could ...
CVE-2024-29904HIGH7.5CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. ...
CVE-2024-29901HIGH8.1The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with N...
CVE-2024-29900HIGH7.5Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files...
CVE-2024-29686HIGH7.2Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary ...
CVE-2024-3081MEDIUM5.4A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulne...
CVE-2024-30508CRITICAL9.8Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through ...
CVE-2024-30507LOW2.7Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through...
CVE-2024-30506HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All...
CVE-2024-30505MEDIUM6.5Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th...
CVE-2024-30504HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.T...
CVE-2024-30502CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.T...
CVE-2024-29893MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have...
CVE-2024-29890HIGH8.8DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation o...
CVE-2024-29202CRITICAL9.9JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit ...
CVE-2024-29201CRITICAL9.9JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass t...
CVE-2024-29024MEDIUM5.3JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user ...
CVE-2024-29020MEDIUM5.3JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker...
CVE-2024-28867HIGH7.4Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now