2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47337MEDIUM4.3Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr...
CVE-2024-47044MEDIUM5.3Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to...
CVE-2024-8861MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-47197HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M...
CVE-2024-47145MEDIUM4.3Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels...
CVE-2024-47003MEDIUM6.5Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a str...
CVE-2024-45843MEDIUM5.4Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denyli...
CVE-2024-42406MEDIUM5.4Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize req...
CVE-2024-4278LOW2.7An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2...
CVE-2024-6517MEDIUM6.1The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputtin...
CVE-2024-0133LOW3.4NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a speciall...
CVE-2024-0132HIGH8.3NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de...
CVE-2024-7781CRITICAL9.8The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7...
CVE-2024-7772CRITICAL9.8The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation...
CVE-2024-45836MEDIUM6.1Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logg...
CVE-2024-45372MEDIUM6.5MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious pa...
CVE-2024-47045HIGH7.8Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, ...
CVE-2024-8803MEDIUM6.1The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-8723MEDIUM5.4The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in al...
CVE-2024-8552MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-47330HIGH8.8Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i...
CVE-2024-8405MEDIUM5.5An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl...
CVE-2024-8404HIGH7.8An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print...
CVE-2024-47083HIGH7.5Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior...
CVE-2024-47315HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now