2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1698CRITICAL9.8The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for...
CVE-2024-1687MEDIUM5.4The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized e...
CVE-2024-1686MEDIUM4.3The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing author...
CVE-2024-0759HIGH7.5Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission l...
CVE-2024-1323MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type ...
CVE-2024-25711HIGH7.5diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ....
CVE-2024-24100HIGH8.3Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
CVE-2024-24099MEDIUM5.4Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
CVE-2024-24096HIGH7.8Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
CVE-2024-24095CRITICAL9.8Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
CVE-2024-22917HIGH8.6SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute ar...
CVE-2024-27356HIGH7.5An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially ...
CVE-2024-25166MEDIUM6.1Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfil...
CVE-2024-24720MEDIUM5.3An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information ...
CVE-2024-22544HIGH8An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbi...
CVE-2024-22543MEDIUM6.1An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges ...
CVE-2024-24721MEDIUM6.5An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute ...
CVE-2024-25247CRITICAL9.8SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL c...
CVE-2024-27093HIGH7.5Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to re...
CVE-2024-25751CRITICAL9.8A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote...
CVE-2024-25248CRITICAL9.8SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary S...
CVE-2024-27089Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not in the allowed sc...
CVE-2024-26149MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified...
CVE-2024-24564MEDIUM5.3Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star...
CVE-2024-24528Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now