2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9973CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an ...
CVE-2024-47945CRITICAL9.8The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The...
CVE-2024-9985CRITICAL9.8Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privil...
CVE-2024-9984CRITICAL9.8Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re...
CVE-2024-9983HIGH7.5Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo...
CVE-2024-9925CRITICAL9.8SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow...
CVE-2024-9895MEDIUM5.4The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo...
CVE-2024-47944MEDIUM6.8The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin ...
CVE-2024-47943CRITICAL9.8The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c...
CVE-2024-9982CRITICAL9.8AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Cam...
CVE-2024-9981HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9980HIGH8.8The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul...
CVE-2024-9837HIGH7.3The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution ...
CVE-2024-9972CRITICAL9.8Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to...
CVE-2024-46898HIGH7.5SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If t...
CVE-2024-9944MEDIUM6.1The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This i...
CVE-2024-0129HIGH7.8NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe...
CVE-2024-21535MEDIUM6.1Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property d...
CVE-2024-9971HIGH8.8The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing...
CVE-2024-9970HIGH8.8The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular priv...
CVE-2024-9969MEDIUM5.4NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert ...
CVE-2024-9968HIGH8.8WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in...
CVE-2024-9952MEDIUM4.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so...
CVE-2024-9820HIGH7.5The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i...
CVE-2024-9687HIGH8.8The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now