2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27094HIGH7.4OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes...
CVE-2024-26196MEDIUM4.3Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
CVE-2024-25811MEDIUM6.5An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
CVE-2024-25359MEDIUM6.6An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of ...
CVE-2024-25239CRITICAL9.8SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm...
CVE-2024-25167MEDIUM6.1Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script...
CVE-2024-24818MEDIUM5.9EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "P...
CVE-2024-24813HIGH7.5Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular ...
CVE-2024-24520HIGH7.8An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languag...
CVE-2024-24110MEDIUM6.5SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET r...
CVE-2024-24028MEDIUM5.9Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information...
CVE-2024-22352MEDIUM5.5IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a loc...
CVE-2024-1908MEDIUM6.5An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us...
CVE-2024-1503MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2024-1502MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due...
CVE-2024-1450MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2024-1326MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all v...
CVE-2024-1278MEDIUM5.4The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-1214MEDIUM4.3The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2024-1213MEDIUM4.3The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2024-1202CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe...
CVE-2024-1142MEDIUM5.4Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files...
CVE-2024-0966MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2024-2748MEDIUM4.3A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execut...
CVE-2024-28916HIGH8.8Xbox Gaming Services Elevation of Privilege Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now