2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-43315HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Ch...
CVE-2024-43288HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo F...
CVE-2024-43286HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugi...
CVE-2024-43282HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS....
CVE-2024-43279HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant N...
CVE-2024-43266HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue aff...
CVE-2024-43246HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon ...
CVE-2024-43244HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes ...
CVE-2024-43241HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate ...
CVE-2024-43239HIGH8.1Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.T...
CVE-2024-43207HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Valiano Unite Gall...
CVE-2024-43145HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDir...
CVE-2024-43303HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in videouserma...
CVE-2024-7910HIGH7.2A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by thi...
CVE-2024-6221HIGH7.5A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to...
CVE-2024-7906HIGH8.8A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type...
CVE-2024-43348HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iznyn Purit...
CVE-2024-7905HIGH7.2A vulnerability classified as critical has been found in DedeBIZ 6.3.0. This affects the function AdminUpload of the fil...
CVE-2024-7904HIGH8.8A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functi...
CVE-2024-7903HIGH8.8A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unkno...
CVE-2024-7899HIGH7.2A vulnerability, which was classified as critical, has been found in InnoCMS 0.3.1. This issue affects some unknown proc...
CVE-2024-7897HIGH8.8A vulnerability classified as critical has been found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04...
CVE-2024-7896HIGH8.8A vulnerability was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. It has been rated as criti...
CVE-2024-43858HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jfs: Fix array-index-out-of-bounds in diFree
CVE-2024-43852HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc2991) re-order conditions to fix off by ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now