2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9172MEDIUM5.4The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-8967MEDIUM5.4The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-8800MEDIUM6.1The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and m...
CVE-2024-8254MEDIUM6.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-9333MEDIUM5.3Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited am...
CVE-2024-9174MEDIUM5.4Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
CVE-2024-7315HIGH7.5The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ...
CVE-2024-7855HIGH8.8The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-45186CRITICAL9.8FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
CVE-2024-33662HIGH7.5Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-21530MEDIUM4.5Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, ...
CVE-2024-9407MEDIUM4.7A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not pro...
CVE-2024-47609MEDIUM6.9Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server ther...
CVE-2024-47528MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach...
CVE-2024-47527MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47526LOW2.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulne...
CVE-2024-47525MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47524MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Gro...
CVE-2024-47523MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-46084HIGH8Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
CVE-2024-46082MEDIUM5.4Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parame...
CVE-2024-46080HIGH8Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
CVE-2024-9411MEDIUM5.3A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admi...
CVE-2024-45999CRITICAL9.8A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function loca...
CVE-2024-9355MEDIUM6.5A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now