2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28034MEDIUM5.4Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web ...
CVE-2024-28033HIGH7.3OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker...
CVE-2024-26018MEDIUM6.1Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of th...
CVE-2024-24805MEDIUM5.3Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Gener...
CVE-2024-2889MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister L...
CVE-2024-2888MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and ...
CVE-2024-2303MEDIUM6.4The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shor...
CVE-2024-2170MEDIUM5.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page in...
CVE-2024-1745MEDIUM4.3The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities...
CVE-2024-29199MEDIUM5.3Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to ...
CVE-2024-29196LOW2.7phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path T...
CVE-2024-29195HIGH8.1The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used ...
CVE-2024-29189HIGH7.8PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ans...
CVE-2024-0866HIGH8.1The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and in...
CVE-2024-2732MEDIUM5.4The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_...
CVE-2024-29303CRITICAL9.8The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CVE-2024-29302HIGH7.5SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.
CVE-2024-29301HIGH7.5SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=
CVE-2024-28421CRITICAL9.8SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updatea...
CVE-2024-0901CRITICAL9.1Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via...
CVE-2024-2873CRITICAL9.1A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create...
CVE-2024-29442Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-21914MEDIUM5.3 A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelVie...
CVE-2024-1973HIGH8.5By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to ele...
CVE-2024-2427HIGH7.5 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now