2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48955HIGH8.1Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi...
CVE-2024-9990HIGH8.8The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This...
CVE-2024-8924HIGH7.5ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability...
CVE-2024-50466HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm...
CVE-2024-7985HIGH8.8The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ...
CVE-2024-49769HIGH7.5Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ...
CVE-2024-7962HIGH7.5An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio...
CVE-2024-7807HIGH7.5A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi...
CVE-2024-7783HIGH7.5mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,...
CVE-2024-7474HIGH8.1In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o...
CVE-2024-6674HIGH7.1A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc...
CVE-2024-41153HIGH7.2Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a...
CVE-2024-10467HIGH8.8Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ...
CVE-2024-10466HIGH7.5By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ...
CVE-2024-10459HIGH7.5An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras...
CVE-2024-10458HIGH7.5A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu...
CVE-2024-49650HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xarbo BuddyPress G...
CVE-2024-49648HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Capt...
CVE-2024-49647HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simpl...
CVE-2024-49646HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ioannup Code Gener...
CVE-2024-49678HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js a...
CVE-2024-10436HIGH8.8The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
CVE-2024-50481HIGH8.8Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E...
CVE-2024-47401HIGH7.5Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b...
CVE-2024-22065HIGH8.8There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now