2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1061CRITICAL9.8The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerabilit...
CVE-2024-21803HIGH7.8Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution ...
CVE-2024-22648MEDIUM5.3A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it poss...
CVE-2024-22647MEDIUM5.3An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a d...
CVE-2024-22646MEDIUM5.3An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allow...
CVE-2024-22643MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unautho...
CVE-2024-1029MEDIUM6.1A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. Affected by this issue is some unknow...
CVE-2024-21488CRITICAL9.8Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_proce...
CVE-2024-1028MEDIUM6.1A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by ...
CVE-2024-21840HIGH7.1Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and...
CVE-2024-1027CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is ...
CVE-2024-22938HIGH7.8Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri...
CVE-2024-22682Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-1026MEDIUM6.1A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown proce...
CVE-2024-1024MEDIUM6.1A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnera...
CVE-2024-23829MEDIUM6.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python H...
CVE-2024-23334HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and c...
CVE-2024-1022MEDIUM4.8A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6...
CVE-2024-1021CRITICAL9.8A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the ...
CVE-2024-1020MEDIUM6.1A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the functi...
CVE-2024-24141CRITICAL9.8Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
CVE-2024-24140HIGH7.2Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
CVE-2024-24139HIGH7.2Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
CVE-2024-24136MEDIUM6.1The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cro...
CVE-2024-22570MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now