2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57611LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&s...
CVE-2024-57162HIGH7.2Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
CVE-2024-57161MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit...
CVE-2024-57160MEDIUM4.307FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
CVE-2024-57159LOW3.507FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add....
CVE-2024-50563CRITICAL9.8A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, F...
CVE-2024-13387MEDIUM6.4The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor...
CVE-2024-13355MEDIUM5.4The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi...
CVE-2024-12615MEDIUM6.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac...
CVE-2024-12614MEDIUM4.3The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-12613HIGH7.5The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu...
CVE-2024-12427MEDIUM5.3The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c...
CVE-2024-48885CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder...
CVE-2024-45331HIGH7.8A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 throug...
CVE-2024-12226MEDIUM6.5In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s...
CVE-2024-11452MEDIUM6.4The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-10789MEDIUM4.3The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-10970MEDIUM5.4The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i...
CVE-2024-10401Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-57728HIGH7.2SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file s...
CVE-2024-57727HIGH7.5SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl...
CVE-2024-57726CRITICAL9.9SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat...
CVE-2024-55503LOW3.3An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_IN...
CVE-2024-53407LOW3.3In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially le...
CVE-2024-41454MEDIUM6.5An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now