2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40579MEDIUM5.4Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to ...
CVE-2024-39707MEDIUM5.3Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by def...
CVE-2024-31695CRITICAL9.8A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attacker...
CVE-2024-9834CRITICAL9.3Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that ...
CVE-2024-9832CRITICAL9.3There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clin...
CVE-2024-51687HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This is...
CVE-2024-51684HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issu...
CVE-2024-51688HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verific...
CVE-2024-49025MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-10397HIGH7.8A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
CVE-2024-10396MEDIUM6.5An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, pos...
CVE-2024-10394HIGH7.8A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing th...
CVE-2024-52370CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a ...
CVE-2024-52369CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shel...
CVE-2024-3760HIGH7.5In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom...
CVE-2024-5125HIGH7.3parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input ...
CVE-2024-52524MEDIUM6.9Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discove...
CVE-2024-52396HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi...
CVE-2024-52393HIGH7.2Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-...
CVE-2024-52384CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, ...
CVE-2024-52383HIGH7.5Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in On...
CVE-2024-52382CRITICAL9.8Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue ...
CVE-2024-52381HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52380CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web...
CVE-2024-52379CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now