2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1125MEDIUM5.4The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data d...
CVE-2024-1124MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending ...
CVE-2024-1123MEDIUM6.5The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification o...
CVE-2024-25951HIGH8A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the under...
CVE-2024-28184HIGH7.4WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attach...
CVE-2024-28180MEDIUM4.3Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An atta...
CVE-2024-28176MEDIUM5.9jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web ...
CVE-2024-28122MEDIUM6.8 JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerabili...
CVE-2024-28754HIGH7.5RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via ...
CVE-2024-28753MEDIUM6.5RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.
CVE-2024-2339HIGH8.8PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user...
CVE-2024-2338HIGH7.5PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to supe...
CVE-2024-21901MEDIUM4.7A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authe...
CVE-2024-21900MEDIUM6.5An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnera...
CVE-2024-21899CRITICAL9.8An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2024-2319MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could sto...
CVE-2024-2318HIGH7.5A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affect...
CVE-2024-2317CRITICAL9.1A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affect...
CVE-2024-2316MEDIUM4.3A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnera...
CVE-2024-2298MEDIUM4.3The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi...
CVE-2024-1851MEDIUM6.5The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi...
CVE-2024-27613HIGH7.3Numbas editor before 7.3 mishandles reading of themes and extensions.
CVE-2024-27612MEDIUM6.2Numbas editor before 7.3 mishandles editing of themes and extensions.
CVE-2024-1987MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor...
CVE-2024-2285MEDIUM6.1A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. A...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now