2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52786CRITICAL9.8An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a...
CVE-2024-50645CRITICAL9.8MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access ...
CVE-2024-53494HIGH7.5Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone...
CVE-2024-50644CRITICAL9.8zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to...
CVE-2024-58239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us...
CVE-2024-56179HIGH7.8In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim...
CVE-2024-50641HIGH8.1An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera...
CVE-2024-45438CRITICAL9.1An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. Th...
CVE-2024-57155CRITICAL9.8Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-57154CRITICAL9.8Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted pay...
CVE-2024-57152HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit...
CVE-2024-53495HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon...
CVE-2024-50640CRITICAL9.8jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function
CVE-2024-57157CRITICAL9.8Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-57491HIGH8.8Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to ac...
CVE-2024-39954MEDIUM6.3CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. ...
CVE-2024-12223CRITICAL9.3Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component...
CVE-2024-44373CRITICAL9.8A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create...
CVE-2024-45062MEDIUM6.8A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer tha...
CVE-2024-49827HIGH7.5IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitiv...
CVE-2024-8393MEDIUM6.6The Woocommerce Blocks – Woolook plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-12612HIGH7.5The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac...
CVE-2024-12575MEDIUM5.3The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Expo...
CVE-2024-12573Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24752 Reason: This candidate is a r...
CVE-2024-37945MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now