2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50421MEDIUM5.3Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa...
CVE-2024-48573CRITICAL9.8A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and admin...
CVE-2024-48572MEDIUM5.3A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres...
CVE-2024-48138CRITICAL9.8A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16...
CVE-2024-44081CRITICAL9.8In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in ...
CVE-2024-44080HIGH7.5In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resul...
CVE-2024-10488HIGH8.8Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap c...
CVE-2024-10487HIGH8.8Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds m...
CVE-2024-10228LOW3.3The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified...
CVE-2024-8587HIGH7.8A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Ov...
CVE-2024-50456HIGH8.8Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-50455HIGH8.8Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-48461MEDIUM4.8Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitr...
CVE-2024-48206CRITICAL9.8A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.
CVE-2024-48063CRITICAL9.8In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is...
CVE-2024-48955HIGH8.1Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi...
CVE-2024-9990HIGH8.8The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This...
CVE-2024-9989CRITICAL9.8The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d...
CVE-2024-9988CRITICAL9.8The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d...
CVE-2024-8924HIGH7.5ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability...
CVE-2024-50466HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm...
CVE-2024-50459CRITICAL9.8Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured ...
CVE-2024-10491MEDIUM5.3A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in...
CVE-2024-8923CRITICAL10ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability c...
CVE-2024-7985HIGH8.8The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now