2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-45887HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45885HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45884HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45882HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...
CVE-2024-51672HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper Better...
CVE-2024-51665MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor ...
CVE-2024-51582HIGH8.8Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion...
CVE-2024-51408MEDIUM6.5AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to ...
CVE-2024-51253HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51251HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51249HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51246HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-50531CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toa...
CVE-2024-50530HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al...
CVE-2024-50529HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We...
CVE-2024-50528HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui...
CVE-2024-50527CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-buil...
CVE-2024-50526CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose...
CVE-2024-50525CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Sh...
CVE-2024-50523CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactf...
CVE-2024-45164HIGH7.1Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la...
CVE-2024-9147MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik...
CVE-2024-51561HIGH7.5This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. A...
CVE-2024-51560MEDIUM4.3This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint....
CVE-2024-51559MEDIUM6.5This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticate...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now