2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4279MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2024-3644MEDIUM4.8The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-3642MEDIUM6.9The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow a...
CVE-2024-3641MEDIUM6.1The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauth...
CVE-2024-4929MEDIUM4.3A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affect...
CVE-2024-4984MEDIUM6.4The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in al...
CVE-2024-4926MEDIUM6.5A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been cla...
CVE-2024-4925MEDIUM6.5A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified a...
CVE-2024-4922MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This a...
CVE-2024-35184MEDIUM5.5Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Start...
CVE-2024-35183MEDIUM4.4wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a...
CVE-2024-4976MEDIUM5.5Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
CVE-2024-4950MEDIUM6.5Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convince...
CVE-2024-4949MEDIUM6.5Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corru...
CVE-2024-4948MEDIUM6.5Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-4911MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. A...
CVE-2024-27243MEDIUM6.5Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via...
CVE-2024-4910MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical...
CVE-2024-4904MEDIUM6.3A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This i...
CVE-2024-34913MEDIUM5.4An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code vi...
CVE-2024-34909MEDIUM5.4An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploadin...
CVE-2024-34906MEDIUM5.4An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a cr...
CVE-2024-31410MEDIUM6.5The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. Thi...
CVE-2024-4909MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critic...
CVE-2024-4908MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now