2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28119HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ...
CVE-2024-28118HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ...
CVE-2024-28117HIGH8.8Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible function...
CVE-2024-28116HIGH8.8Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-...
CVE-2024-28029HIGH8.8Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authoriza...
CVE-2024-27921HIGH8.8Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identif...
CVE-2024-25937HIGH8.8 SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.
CVE-2024-24272HIGH7.1An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive inf...
CVE-2024-2767MEDIUM6.5A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. T...
CVE-2024-2766MEDIUM6.5A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critic...
CVE-2024-2764HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formS...
CVE-2024-2763HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is ...
CVE-2024-28756MEDIUM5.9The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machi...
CVE-2024-1727MEDIUM4.3A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files t...
CVE-2024-29374MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" U...
CVE-2024-2580MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automati...
CVE-2024-2579MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking C...
CVE-2024-2578MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder a...
CVE-2024-29916MEDIUM5.6The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a p...
CVE-2024-29180HIGH7.5Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not valida...
CVE-2024-27968MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue...
CVE-2024-27965MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnel...
CVE-2024-27964HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: ...
CVE-2024-27963MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Store...
CVE-2024-27962MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now