2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-6637HIGH7.3The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all version...
CVE-2024-6635HIGH7.3The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ...
CVE-2024-38696HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zo...
CVE-2024-38694HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Moloni allo...
CVE-2024-38683HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iThemelandC...
CVE-2024-38680HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Ap...
CVE-2024-38673HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Info...
CVE-2024-38672HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in namithjawah...
CVE-2024-38669HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in a3rev Softw...
CVE-2024-37961HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codoc.Jp al...
CVE-2024-6281HIGH7.3A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `...
CVE-2024-40348HIGH8.2An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory...
CVE-2024-41122HIGH8.8Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t...
CVE-2024-41121HIGH8.8Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t...
CVE-2024-39906HIGH8.3A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app...
CVE-2024-40400HIGH8.8An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr...
CVE-2024-41600HIGH7.5Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive...
CVE-2024-41602HIGH8.8Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privilege...
CVE-2024-41601HIGH7.5Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive informatio...
CVE-2024-41492HIGH7.5A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-41281HIGH8.8Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
CVE-2024-39963HIGH8AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01...
CVE-2024-27489HIGH7.5An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
CVE-2024-37066HIGH8.8A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to ...
CVE-2024-41107HIGH8.1The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now