2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2891HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuic...
CVE-2024-29883MEDIUM4.9CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work...
CVE-2024-29881MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s cont...
CVE-2024-29684CRITICAL9.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage...
CVE-2024-29203MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte...
CVE-2024-1455MEDIUM5.9A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Enti...
CVE-2024-30235HIGH8.8Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page G...
CVE-2024-30234HIGH8.8Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.
CVE-2024-30233MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects...
CVE-2024-2906MEDIUM6.5Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
CVE-2024-22156MEDIUM6.5Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
CVE-2024-1933HIGH7.1Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an atta...
CVE-2024-30232MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons E...
CVE-2024-30231HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is...
CVE-2024-29644MEDIUM6.1Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code v...
CVE-2024-28093HIGH8.8The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for ...
CVE-2024-24799HIGH8.8Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: fro...
CVE-2024-24719MEDIUM4.3Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Loca...
CVE-2024-24718MEDIUM6.5Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
CVE-2024-24711MEDIUM4.3Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion ...
CVE-2024-23520MEDIUM4.3Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
CVE-2024-2904HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through ...
CVE-2024-28131HIGH7.8EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer,...
CVE-2024-28126MEDIUM6.1Cross-site scripting vulnerability exists in 0ch BBS Script ver.4.00. An arbitrary script may be executed on the web bro...
CVE-2024-28048CRITICAL9.8OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now