2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1500MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo ...
CVE-2024-1377MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_ta...
CVE-2024-1366MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_...
CVE-2024-28216MEDIUM5.4nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which ...
CVE-2024-28215HIGH7.5nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which ...
CVE-2024-28214LOW2.7nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote at...
CVE-2024-28213CRITICAL9.8nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote atta...
CVE-2024-28212CRITICAL9.8nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via uns...
CVE-2024-28211CRITICAL9.8nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing ar...
CVE-2024-1761MEDIUM5.4The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all v...
CVE-2024-28097MEDIUM5.4Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting all...
CVE-2024-28096MEDIUM5.4Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowi...
CVE-2024-28095MEDIUM5.4News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing...
CVE-2024-28094HIGH8.8Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the au...
CVE-2024-0815HIGH8.8Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0
CVE-2024-1460MEDIUM4.4MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code...
CVE-2024-1443MEDIUM4.4MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code ...
CVE-2024-24389MEDIUM6.1A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts o...
CVE-2024-0817HIGH7.8Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
CVE-2024-26566HIGH8.2An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification co...
CVE-2024-24375HIGH7.5SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/adm...
CVE-2024-22857CRITICAL9.8Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but...
CVE-2024-1299HIGH8.1A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to ...
CVE-2024-0199HIGH8An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to ...
CVE-2024-2236MEDIUM5.9A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now