2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42835CRITICAL9.8langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
CVE-2024-8934MEDIUM6.5A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI)...
CVE-2024-10454MEDIUM6.1Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerabilit...
CVE-2024-49685HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds...
CVE-2024-49674CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Uploa...
CVE-2024-43984HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue af...
CVE-2024-43933MEDIUM4.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.Ap...
CVE-2024-43930MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects...
CVE-2024-43383HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's...
CVE-2024-30149MEDIUM6.5HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
CVE-2024-9446MEDIUM6.4The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor ...
CVE-2024-9434MEDIUM6.1The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2024-9430MEDIUM5.3The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized acces...
CVE-2024-9165MEDIUM6.4The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-9700MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D...
CVE-2024-10392CRITICAL9.8The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val...
CVE-2024-21537HIGH8.9Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse...
CVE-2024-9708MEDIUM5.4The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-48311HIGH8.8Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
CVE-2024-10561CRITICAL9.8A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects a...
CVE-2024-10559HIGH7.8A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected b...
CVE-2024-10544MEDIUM5.3The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2024-48307CRITICAL9.8JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD...
CVE-2024-10557MEDIUM6.5A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected...
CVE-2024-10556CRITICAL9.8A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now