2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4712HIGH7.8An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl...
CVE-2024-4681HIGH7.2A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is ...
CVE-2024-4605HIGH8.8The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 v...
CVE-2024-4545HIGH7.7 All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 ma...
CVE-2024-4441HIGH8.1The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl...
CVE-2024-4423HIGH7.2The access control in CemiPark software does not properly validate user-entered data, which allows the authentication by...
CVE-2024-4397HIGH8.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...
CVE-2024-4129HIGH8.8Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to...
CVE-2024-4068HIGH7.5The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could le...
CVE-2024-4044HIGH7.8A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may...
CVE-2024-3954HIGH8.8The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of...
CVE-2024-3940HIGH8.8The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which...
CVE-2024-3903HIGH7.1The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-3828HIGH8.8The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. ...
CVE-2024-3809HIGH8.8The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-3808HIGH8.8The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-3807HIGH8.8The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'por...
CVE-2024-3727HIGH8.3A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authentica...
CVE-2024-3460HIGH7In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened app...
CVE-2024-3459HIGH7.8KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by...
CVE-2024-3055HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ...
CVE-2024-3037HIGH7.8An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print...
CVE-2024-35205HIGH7.8The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names befo...
CVE-2024-35204HIGH8.4Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus lo...
CVE-2024-35166HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Fileb...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now