2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24881MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ...
CVE-2024-24880MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apo...
CVE-2024-24879MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre L...
CVE-2024-24886MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product La...
CVE-2024-22464MEDIUM6.8 Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitiv...
CVE-2024-24034MEDIUM6.1Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers t...
CVE-2024-23452HIGH7.5Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle re...
CVE-2024-1207CRITICAL9.8The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy...
CVE-2024-0965MEDIUM5.3The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-24216CRITICAL9.8Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection met...
CVE-2024-24091CRITICAL9.8Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file up...
CVE-2024-0511MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-24202CRITICAL9.8An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and...
CVE-2024-25148HIGH8.1In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 be...
CVE-2024-25146MEDIUM5.3Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor...
CVE-2024-25144MEDIUM6.5The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before u...
CVE-2024-24021CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24017CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24014CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24003CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon...
CVE-2024-22394CRITICAL9.8An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con...
CVE-2024-24350HIGH8.8File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary...
CVE-2024-24026CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controll...
CVE-2024-24025CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileCo...
CVE-2024-24024CRITICAL9.8An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.File...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now