2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-52519HIGH8.2Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so ...
CVE-2024-50654HIGH7.5lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quant...
CVE-2024-50653HIGH7.5CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able t...
CVE-2024-44625HIGH8.8Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
CVE-2024-39726HIGH8.2IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In...
CVE-2024-11248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function f...
CVE-2024-52555HIGH7.8In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer...
CVE-2024-50650HIGH7.5python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of us...
CVE-2024-50647HIGH7.5The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user infor...
CVE-2024-41784HIGH7.5IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse dire...
CVE-2024-11245HIGH7.5A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0. This issue affects some...
CVE-2024-50986HIGH7.3An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.
CVE-2024-11242HIGH7.2A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona...
CVE-2024-11241HIGH7.5A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulne...
CVE-2024-10311HIGH8.8The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and i...
CVE-2024-45784HIGH7.5Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in tas...
CVE-2024-49778HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service ...
CVE-2024-49777HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-41209HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-51659HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XS...
CVE-2024-51658HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.Thi...
CVE-2024-50968HIGH7.5A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1....
CVE-2024-51687HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This is...
CVE-2024-51684HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issu...
CVE-2024-51688HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verific...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now