2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-11241HIGH7.5A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulne...
CVE-2024-10311HIGH8.8The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and i...
CVE-2024-45784HIGH7.5Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in tas...
CVE-2024-49778HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service ...
CVE-2024-49777HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-41209HIGH8.8A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ...
CVE-2024-51659HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XS...
CVE-2024-51658HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.Thi...
CVE-2024-50968HIGH7.5A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1....
CVE-2024-51687HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This is...
CVE-2024-51684HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issu...
CVE-2024-51688HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verific...
CVE-2024-10397HIGH7.8A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
CVE-2024-10394HIGH7.8A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing th...
CVE-2024-3760HIGH7.5In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom...
CVE-2024-5125HIGH7.3parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input ...
CVE-2024-52396HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi...
CVE-2024-52393HIGH7.2Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-...
CVE-2024-52383HIGH7.5Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in On...
CVE-2024-52381HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52378HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass...
CVE-2024-52371HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway ...
CVE-2024-50831HIGH7.2A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the usernam...
CVE-2024-50830HIGH7.2A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Proje...
CVE-2024-50829HIGH7.2A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now