2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46054CRITICAL9.8OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, all...
CVE-2024-11862MEDIUM5.1Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render hal...
CVE-2024-53635MEDIUM4.8A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV...
CVE-2024-53604CRITICAL9.8A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management S...
CVE-2024-53603HIGH7.3A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management Sy...
CVE-2024-36464LOW2.7When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type...
CVE-2024-42333LOW2.7The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read...
CVE-2024-42332LOW3.7The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with addit...
CVE-2024-42331LOW3.3In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript...
CVE-2024-42330CRITICAL9.1The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem ...
CVE-2024-42329LOW3.3The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function...
CVE-2024-42328MEDIUM5.5When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo...
CVE-2024-42327CRITICAL9.9A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access...
CVE-2024-42326MEDIUM4.4There was discovered a use after free bug in browser.c in the es_browser_get_variant function
CVE-2024-36468HIGH8.2The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix s...
CVE-2024-11009MEDIUM4.9The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable...
CVE-2024-11025MEDIUM5.4An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat...
CVE-2024-10521MEDIUM4.3The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2024-52323HIGH8.1Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which a...
CVE-2024-11667CRITICAL9.8A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through ...
CVE-2024-36467HIGH8.8An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the u...
CVE-2024-10895MEDIUM6.4The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-10580MEDIUM5.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form su...
CVE-2024-10175MEDIUM6.4The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro...
CVE-2024-52959HIGH7.2A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversation...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now