2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6019MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could...
CVE-2024-6018MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2024-6017MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisat...
CVE-2024-5799MEDIUM4.8The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which cou...
CVE-2024-3163MEDIUM4.3The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which ...
CVE-2024-45624HIGH7.5Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a ...
CVE-2024-8711HIGH7.5A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1...
CVE-2024-8710HIGH8.8A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerabili...
CVE-2024-8709HIGH8.8A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affecte...
CVE-2024-38222MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-8708MEDIUM6.1A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. T...
CVE-2024-37397HIGH8.2An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 Se...
CVE-2024-34785HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-34783HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-34779HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32848HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32846HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32845HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32843HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32842HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-32840HIGH7.2An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a...
CVE-2024-29847CRITICAL9.8Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows...
CVE-2024-8707MEDIUM5.3A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. Thi...
CVE-2024-8706MEDIUM6.5A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function ...
CVE-2024-28981HIGH8.5Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now