2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45490HIGH7.5An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CVE-2024-2881HIGH8.8Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6...
CVE-2024-1545HIGH8.8Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on...
CVE-2024-6672HIGH8.8In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged ...
CVE-2024-45302HIGH7.8RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu...
CVE-2024-34019HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...
CVE-2024-34017HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...
CVE-2024-43804HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi...
CVE-2024-41964HIGH8.1Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o...
CVE-2024-35133HIGH8.2IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph...
CVE-2024-43957HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ...
CVE-2024-43955HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil...
CVE-2024-43943HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-43942HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-39658HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking Syst...
CVE-2024-39638HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registr...
CVE-2024-39620HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio Listi...
CVE-2024-38793HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Re...
CVE-2024-38693HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Fro...
CVE-2024-8297HIGH7.5A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. A...
CVE-2024-3679HIGH7.5The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all version...
CVE-2024-2541HIGH7.5The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-7856HIGH8.1The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized...
CVE-2024-7607HIGH8.8The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all vers...
CVE-2024-5623HIGH7.8An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now