2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52958HIGH7.2A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platfo...
CVE-2024-11219HIGH7.5The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path ...
CVE-2024-11083MEDIUM5.3The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-5921HIGH8.8An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect ...
CVE-2024-53676CRITICAL9.8A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution...
CVE-2024-11820MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This is...
CVE-2024-53849MEDIUM4.8editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing)....
CVE-2024-11819CRITICAL9.8A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit...
CVE-2024-11818CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System...
CVE-2024-11817CRITICAL9.8A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as c...
CVE-2024-53675HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-53674HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-53673CRITICAL9.8A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code...
CVE-2024-11622HIGH7.5An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in...
CVE-2024-50942CRITICAL9.8qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.
CVE-2024-43784MEDIUM5.7lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have ...
CVE-2024-11745CRITICAL9.8A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro...
CVE-2024-11744CRITICAL9.8A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected...
CVE-2024-8676HIGH7.4A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a...
CVE-2024-49053HIGH7.6Microsoft Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-49052CRITICAL9.8Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p...
CVE-2024-49038CRITICAL9.6Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorize...
CVE-2024-49035CRITICAL9.8An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil...
CVE-2024-11743MEDIUM4.3A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1....
CVE-2024-11742MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now