2024 CVE Vulnerabilities

39,233 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50476CRITICAL9.8Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege ...
CVE-2024-50475CRITICAL9.8Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affect...
CVE-2024-50473CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em...
CVE-2024-50427CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects Surv...
CVE-2024-50426MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak...
CVE-2024-50420CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Sh...
CVE-2024-50418MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking ...
CVE-2024-50415MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Ads.txt & Ap...
CVE-2024-50414MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buttonizer Button ...
CVE-2024-50413MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Impo...
CVE-2024-50412MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Condit...
CVE-2024-50411MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Ab...
CVE-2024-49642MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi Todo Cus...
CVE-2024-47401HIGH7.5Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b...
CVE-2024-46872MEDIUM4.6Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that...
CVE-2024-45477MEDIUM4.6Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Paramete...
CVE-2024-22066MEDIUM6.5There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated at...
CVE-2024-10048MEDIUM6.1The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2024-50494CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-suda...
CVE-2024-50493CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translat...
CVE-2024-50484CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose...
CVE-2024-50482CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-d...
CVE-2024-50480CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO marketing-automatio...
CVE-2024-50052MEDIUM4.3Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in a...
CVE-2024-10312MEDIUM4.3The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now