2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48234MEDIUM4.9An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAd...
CVE-2024-48228MEDIUM6.1An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the ...
CVE-2024-48396MEDIUM6.1AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the ...
CVE-2024-48233MEDIUM4.8mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP param...
CVE-2024-48232MEDIUM4.9An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the p...
CVE-2024-48230HIGH7.2funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\a...
CVE-2024-48229HIGH7.2funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
CVE-2024-48227MEDIUM4.9Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Servi...
CVE-2024-48226HIGH7.2Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
CVE-2024-48225MEDIUM6.5Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
CVE-2024-48224MEDIUM4.9Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
CVE-2024-48223HIGH7.2Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
CVE-2024-48222HIGH7.2Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
CVE-2024-48218HIGH7.2Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
CVE-2024-49767HIGH7.5Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartPar...
CVE-2024-49766MEDIUM5.3Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does no...
CVE-2024-48450MEDIUM6.5An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploadin...
CVE-2024-37847HIGH8.8An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute ar...
CVE-2024-37846MEDIUM4.6MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Ma...
CVE-2024-37845HIGH7.2MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active...
CVE-2024-37844MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scri...
CVE-2024-9585MEDIUM5.4The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with...
CVE-2024-9584MEDIUM5.4The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss...
CVE-2024-48700HIGH7.2Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or ge...
CVE-2024-48448MEDIUM6.1An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploadin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now