2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6445HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology Dat...
CVE-2024-44837MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute ...
CVE-2024-45405MEDIUM6`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their con...
CVE-2024-45300MEDIUM5.9alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2024-45299MEDIUM6.5alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2024-45040MEDIUM5.9gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments t...
CVE-2024-45039MEDIUM6.2gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundn...
CVE-2024-44739HIGH8.8Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-1744HIGH7.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allow...
CVE-2024-8427MEDIUM4.3The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau...
CVE-2024-8317MEDIUM5.4The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad...
CVE-2024-8292CRITICAL9.8The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/accoun...
CVE-2024-7349HIGH7.2The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injectio...
CVE-2024-6792LOW3.5The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public p...
CVE-2024-45751MEDIUM5.9tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed ...
CVE-2024-39585HIGH8.1Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Pass...
CVE-2024-38486HIGH8.8Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralizati...
CVE-2024-8480HIGH8.8The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due ...
CVE-2024-8247HIGH8.8The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2...
CVE-2024-7415MEDIUM5.3The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including...
CVE-2024-40865MEDIUM5.3The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. ...
CVE-2024-44082MEDIUM4.3In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, i...
CVE-2024-45400MEDIUM6.1ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possib...
CVE-2024-42495HIGH7.5Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow...
CVE-2024-39278MEDIUM4.6Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now