2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0324HIGH7.5The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2024-0255MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text...
CVE-2024-0254MEDIUM5.4The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post m...
CVE-2024-0221HIGH7.2The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in ...
CVE-2024-24807MEDIUM4.8Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue ...
CVE-2024-24574MEDIUM6.1phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of fi...
CVE-2024-24559MEDIUM5.3Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `I...
CVE-2024-24543CRITICAL9.8Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allo...
CVE-2024-22208MEDIUM6.5phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ'...
CVE-2024-1052HIGH8Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An a...
CVE-2024-0202MEDIUM5.9A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the su...
CVE-2024-22567HIGH8.8File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/...
CVE-2024-22202MEDIUM6.5phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user r...
CVE-2024-24396MEDIUM6.1Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker...
CVE-2024-24267HIGH7.5gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_b...
CVE-2024-24266HIGH7.5gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src...
CVE-2024-24265HIGH7.5gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_int...
CVE-2024-24263HIGH7.5Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_lin...
CVE-2024-24262HIGH7.5media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function a...
CVE-2024-24260HIGH7.5media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function...
CVE-2024-24259HIGH7.5freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry functi...
CVE-2024-24258HIGH7.5freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
CVE-2024-0953MEDIUM6.1When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the pag...
CVE-2024-24469HIGH8.8Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th...
CVE-2024-24468HIGH8.8Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now