2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0611MEDIUM4.8The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sl...
CVE-2024-0378MEDIUM6.1The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-1775MEDIUM5.4The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting ...
CVE-2024-1592MEDIUM4.3The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-25064MEDIUM4.3Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the at...
CVE-2024-25063HIGH7.5Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain a...
CVE-2024-27355HIGH7.5An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the AS...
CVE-2024-27354HIGH7.5An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can constr...
CVE-2024-25438MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrar...
CVE-2024-25436MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrar...
CVE-2024-25434MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-24512MEDIUM6.1Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle ...
CVE-2024-24511MEDIUM6.1Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title com...
CVE-2024-27747CRITICAL9.8File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra...
CVE-2024-27746CRITICAL9.8SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c...
CVE-2024-27744MEDIUM6.1Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ...
CVE-2024-27743MEDIUM6.1Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ...
CVE-2024-1869HIGH7.5Certain HP DesignJet print products are potentially vulnerable to information disclosure related to accessing memory out...
CVE-2024-27101CRITICAL9.1SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per...
CVE-2024-23492MEDIUM5.7 A weak encoding is used to transmit credentials for WS203VICM.
CVE-2024-22182HIGH8.6A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM caus...
CVE-2024-21767CRITICAL9.4 A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.
CVE-2024-20328MEDIUM5.3A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the p...
CVE-2024-1174HIGH8.2Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP ha...
CVE-2024-2077CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now