2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1184MEDIUM5.5A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is...
CVE-2024-0269HIGH8.8ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary Dril...
CVE-2024-0253HIGH8.8ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
CVE-2024-1201HIGH7.8Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability co...
CVE-2024-0963MEDIUM5.4The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULA...
CVE-2024-0844HIGH7.2The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in ...
CVE-2024-24388MEDIUM6.1Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sens...
CVE-2024-23895MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...
CVE-2024-0338CRITICAL9.8A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute a...
CVE-2024-25001Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID. ConsultIDs: none. Reason: This CVE ID is unused by its CNA. Notes:...
CVE-2024-22851HIGH7.5Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information ...
CVE-2024-24524HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code...
CVE-2024-23978CRITICAL9.8Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbit...
CVE-2024-21863MEDIUM6.2 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2024-21860HIGH8.8 in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use a...
CVE-2024-21851HIGH7.8 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.
CVE-2024-21845HIGH7.8 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.
CVE-2024-21780HIGH7.5Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted com...
CVE-2024-0285MEDIUM5.5 in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2024-1162MEDIUM4.3The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-1143MEDIUM6.1Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of...
CVE-2024-1047MEDIUM5.3Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data ...
CVE-2024-24482CRITICAL9.8Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
CVE-2024-21485MEDIUM5.4Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; v...
CVE-2024-1073MEDIUM5.4The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' paramete...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now