2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38749HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import all...
CVE-2024-38747HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Paym...
CVE-2024-38724HIGH7.1Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scrip...
CVE-2024-38699HIGH7.5Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Proper...
CVE-2024-37935HIGH7.5Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrain...
CVE-2024-41977HIGH8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM...
CVE-2024-41976HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM...
CVE-2024-41939HIGH8.8A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enfor...
CVE-2024-41908HIGH7.8A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of boun...
CVE-2024-41904HIGH7.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a...
CVE-2024-41903HIGH7.2A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a...
CVE-2024-41681HIGH7.5A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected pr...
CVE-2024-36398HIGH7.8A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of it...
CVE-2024-6823HIGH8.8The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-42374HIGH8.2BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source...
CVE-2024-43127HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory P...
CVE-2024-43126HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Send...
CVE-2024-37930HIGH7.5Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpr...
CVE-2024-43217HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebe...
CVE-2024-43213HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MultiVendor...
CVE-2024-43163HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Pane...
CVE-2024-7704HIGH7.5A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function o...
CVE-2024-43233HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BannerSky B...
CVE-2024-42748HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42747HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now