2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57968HIGH8.8Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones...
CVE-2024-57669HIGH7.5Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf...
CVE-2024-57498MEDIUM4.8Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the...
CVE-2024-57452HIGH7.5ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows ...
CVE-2024-57450CRITICAL9.8ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
CVE-2024-57099CRITICAL9.8ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in ...
CVE-2024-57098CRITICAL9.8Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into ...
CVE-2024-57097MEDIUM4.8ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-56946MEDIUM5.3Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s...
CVE-2024-56921HIGH7.5An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF ...
CVE-2024-12859HIGH8.8The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-12511HIGH7.6With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This...
CVE-2024-11134MEDIUM6.5The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11133MEDIUM5.3The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11132MEDIUM5.4The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl...
CVE-2024-57238HIGH7.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The ...
CVE-2024-57237MEDIUM6.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp...
CVE-2024-57004MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici...
CVE-2024-50656MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-12510MEDIUM6.7If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T...
CVE-2024-57967MEDIUM4.2PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ...
CVE-2024-57362Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation d...
CVE-2024-57175MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ...
CVE-2024-56161HIGH7.2Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri...
CVE-2024-54840MEDIUM6.1PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now