2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-39638HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registr...
CVE-2024-39620HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio Listi...
CVE-2024-38793HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Re...
CVE-2024-38693HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Fro...
CVE-2024-8297HIGH7.5A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. A...
CVE-2024-3679HIGH7.5The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all version...
CVE-2024-2541HIGH7.5The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-7856HIGH8.1The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized...
CVE-2024-7607HIGH8.8The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all vers...
CVE-2024-5623HIGH7.8An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get ...
CVE-2024-5622HIGH7.8An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may...
CVE-2024-43700HIGH7.8xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-ba...
CVE-2024-45436HIGH7.5extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct...
CVE-2024-8198HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ...
CVE-2024-8194HIGH8.8Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr...
CVE-2024-8193HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ...
CVE-2024-45059HIGH8.8i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators...
CVE-2024-45058HIGH8.1i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators...
CVE-2024-44760HIGH7.5Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0...
CVE-2024-42793HIGH8A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted requ...
CVE-2024-41236HIGH7.2A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an...
CVE-2024-7745HIGH8.1In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra...
CVE-2024-20478HIGH7.2A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco...
CVE-2024-20446HIGH8.6A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cau...
CVE-2024-20286HIGH8.8A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now