2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49740MEDIUM5.5In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser...
CVE-2024-47192MEDIUM5.3An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker ...
CVE-2024-35203MEDIUM6.1Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part o...
CVE-2024-39335CRITICAL9.1Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed...
CVE-2024-47853HIGH8.8An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w...
CVE-2024-45753MEDIUM6.1In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value ...
CVE-2024-8860MEDIUM4.3The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-46413MEDIUM5.1Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild....
CVE-2024-46412MEDIUM6.5Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a cra...
CVE-2024-39923MEDIUM6.1An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer lin...
CVE-2024-48988HIGH7.6SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users...
CVE-2024-53499CRITICAL9.8Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.
CVE-2024-53496CRITICAL9.8Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive compone...
CVE-2024-52786CRITICAL9.8An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a...
CVE-2024-50645CRITICAL9.8MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access ...
CVE-2024-53494HIGH7.5Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone...
CVE-2024-50644CRITICAL9.8zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to...
CVE-2024-58239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us...
CVE-2024-56179HIGH7.8In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim...
CVE-2024-50641HIGH8.1An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera...
CVE-2024-45438CRITICAL9.1An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. Th...
CVE-2024-57155CRITICAL9.8Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-57154CRITICAL9.8Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted pay...
CVE-2024-57152HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit...
CVE-2024-53495HIGH7.5Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now