2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-32488HIGH7.8In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak p...
CVE-2024-2739HIGH8.7The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers...
CVE-2024-1755HIGH8.8The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-0399HIGH8.1The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before ...
CVE-2024-3778HIGH7.2The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attacker...
CVE-2024-3775HIGH7.5aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user inpu...
CVE-2024-3767HIGH8.8A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code ...
CVE-2024-1655HIGH8.8Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to...
CVE-2024-3772HIGH7.5Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service vi...
CVE-2024-29843HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29842HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29841HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29840HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29839HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-29838HIGH7.5The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, a...
CVE-2024-29837HIGH8.8The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing ...
CVE-2024-32487HIGH8.6less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandle...
CVE-2024-3736HIGH7.5A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulne...
CVE-2024-3719HIGH8.8A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affec...
CVE-2024-28869HIGH7.5Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint w...
CVE-2024-32019HIGH8.8Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of t...
CVE-2024-32005HIGH8.2NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component ...
CVE-2024-32003HIGH8.8wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin ...
CVE-2024-29023HIGH7.2Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software...
CVE-2024-29022HIGH8.8Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now