2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10672LOW2.7The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie...
CVE-2024-10538MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label pa...
CVE-2024-49395MEDIUM5.3In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field b...
CVE-2024-49394MEDIUM5.3In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacke...
CVE-2024-8882MEDIUM4.5A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and ea...
CVE-2024-8881MEDIUM6.8A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version ...
CVE-2024-49393MEDIUM6.5In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha...
CVE-2024-11099CRITICAL9.8A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unkno...
CVE-2024-11097MEDIUM5.5A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi...
CVE-2024-47595HIGH7.1An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access....
CVE-2024-47593MEDIUM4.3SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv...
CVE-2024-47592MEDIUM5.3SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the...
CVE-2024-47590HIGH8.8An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated vi...
CVE-2024-47588MEDIUM4.7In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,...
CVE-2024-47587LOW3.5Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of pri...
CVE-2024-47586MEDIUM5.3SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra...
CVE-2024-42372MEDIUM6.5Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a...
CVE-2024-11096MEDIUM6.5A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ...
CVE-2024-11079MEDIUM5.5A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos...
CVE-2024-52533CRITICAL9.8gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CON...
CVE-2024-51213MEDIUM6.1Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the...
CVE-2024-50636CRITICAL9.8PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code e...
CVE-2024-50601MEDIUM6.1Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve...
CVE-2024-25255CRITICAL9.8Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multip...
CVE-2024-25254CRITICAL9.8SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now