2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56112MEDIUM6.1CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-56087MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template...
CVE-2024-56086HIGH7.1An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are...
CVE-2024-56085MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template...
CVE-2024-56084HIGH7.1An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea...
CVE-2024-11841MEDIUM5.4The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be...
CVE-2024-8650MEDIUM5.3An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6...
CVE-2024-8116MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17....
CVE-2024-53376HIGH8.8CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ...
CVE-2024-56083HIGH8.1Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly...
CVE-2024-8798MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-11858HIGH7.8A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation wh...
CVE-2024-7701HIGH7.5Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption B...
CVE-2024-56082LOW3.5ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab...
CVE-2024-56074MEDIUM5.5gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
CVE-2024-55969CRITICAL9.1DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX do...
CVE-2024-56073HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote...
CVE-2024-56072HIGH7.5An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to ca...
CVE-2024-55970HIGH7.5File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the ...
CVE-2024-31892HIGH7.5IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized act...
CVE-2024-31891HIGH7.8IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulner...
CVE-2024-11721HIGH8.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i...
CVE-2024-11720MEDIUM6.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ...
CVE-2024-12628MEDIUM4.4The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete...
CVE-2024-12446MEDIUM6.4The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now