2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10023HIGH8.8A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability aff...
CVE-2024-8040HIGH7.7An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R...
CVE-2024-6380MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX...
CVE-2024-10022CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-10021CRITICAL9.8A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by th...
CVE-2024-8921MEDIUM6.4The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-9444MEDIUM5.4The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up...
CVE-2024-9858HIGH7.8There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo...
CVE-2024-9540MEDIUM4.3The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-9061CRITICAL9.8The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary sho...
CVE-2024-45715MEDIUM5.2The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to exis...
CVE-2024-45714MEDIUM4.1Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v...
CVE-2024-45711HIGH8.8SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible dependi...
CVE-2024-45710HIGH7.8SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This...
CVE-2024-45693HIGH8.8Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ...
CVE-2024-45462HIGH7.1The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex...
CVE-2024-45461MEDIUM6.3The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,...
CVE-2024-45219HIGH8.5Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v...
CVE-2024-45217HIGH8.1Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore...
CVE-2024-45216CRITICAL9.8Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable...
CVE-2024-9582MEDIUM5.4The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an ac...
CVE-2024-8918MEDIUM5.4The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc...
CVE-2024-8746HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi...
CVE-2024-8507HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2024-9937MEDIUM6.1The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now