2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1725MEDIUM6.5A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue coul...
CVE-2024-0203HIGH8.8The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi...
CVE-2024-1773HIGH8.8The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2024-22752HIGH8.1Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use o...
CVE-2024-1442HIGH8.8 A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doin...
CVE-2024-27733HIGH7.7File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitr...
CVE-2024-1351CRITICAL9.8Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which ma...
CVE-2024-2245MEDIUM6.1Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a...
CVE-2024-2241MEDIUM6.3Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user...
CVE-2024-0818CRITICAL9.1Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
CVE-2024-28230MEDIUM6.5In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin p...
CVE-2024-28229MEDIUM6.5In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
CVE-2024-28228MEDIUM5.3In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
CVE-2024-1170HIGH8.2The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-1169HIGH7.5The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-22256MEDIUM4.3VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather ...
CVE-2024-1931HIGH7.5NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of se...
CVE-2024-1534MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2024-2136MEDIUM5.4The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Hea...
CVE-2024-1382HIGH8.8The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ...
CVE-2024-0917CRITICAL9.8remote code execution in paddlepaddle/paddle 2.6.0
CVE-2024-28222CRITICAL9.8In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file...
CVE-2024-1506MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title...
CVE-2024-1419MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attrib...
CVE-2024-1720MEDIUM6.1The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now