2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51939MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Santhosh veer Styl...
CVE-2024-33231MEDIUM5.4Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a c...
CVE-2024-52587HIGH8.8StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted ru...
CVE-2024-52418HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CactusThemes Gamep...
CVE-2024-52417HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes ReConst...
CVE-2024-52394MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in verkkovaraani Prin...
CVE-2024-52390MEDIUM4.9Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects ...
CVE-2024-52389MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job...
CVE-2024-52349MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Shiddikur Rahm...
CVE-2024-52348MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Extensions AA A...
CVE-2024-52347MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator W...
CVE-2024-52346MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JavierMendezPWG Si...
CVE-2024-52345MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RobertoAlicata ra_...
CVE-2024-52344MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeies Pvt Ltd Pr...
CVE-2024-52343MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-52342MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-52341MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio...
CVE-2024-51051CRITICAL9.8AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
CVE-2024-21287HIGH7.5Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Pro...
CVE-2024-10486MEDIUM5.3The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and inclu...
CVE-2024-52585MEDIUM5.4Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vuln...
CVE-2024-52584MEDIUM5.4Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in ver...
CVE-2024-52583HIGH8.2The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen...
CVE-2024-52506MEDIUM6.5Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and sched...
CVE-2024-52304HIGH7.5aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python par...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now