2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11358MEDIUM5.5Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with...
CVE-2024-11144CRITICAL9.2The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The...
CVE-2024-10095CRITICAL9.8In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an i...
CVE-2024-56003MEDIUM4.3Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera S...
CVE-2024-55999MEDIUM5.3Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-gene...
CVE-2024-54376HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-54357MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <=...
CVE-2024-54348MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand ...
CVE-2024-54285CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to ...
CVE-2024-54284HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP...
CVE-2024-54283HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP...
CVE-2024-54280CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBo...
CVE-2024-54279HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki...
CVE-2024-54257HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Ref...
CVE-2024-54249HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Advanc...
CVE-2024-54229CRITICAL9.8Incorrect Privilege Assignment vulnerability in straightvisions GmbH SV100 Companion sv100-companion allows Privilege Es...
CVE-2024-43234CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authenticatio...
CVE-2024-12654MEDIUM5.5A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerabili...
CVE-2024-12653MEDIUM5.5A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the functio...
CVE-2024-56015HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: ...
CVE-2024-56013HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authenticatio...
CVE-2024-56012CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlb...
CVE-2024-56011MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov Respon...
CVE-2024-56009MEDIUM5.3Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality...
CVE-2024-56007MEDIUM4.3Missing Authorization vulnerability in leader codes Leader leader allows Exploiting Incorrectly Configured Access Contro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now