2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8471MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...
CVE-2024-8470HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8469HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8468HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /job...
CVE-2024-8467HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobport...
CVE-2024-8466HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /j...
CVE-2024-8465HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jo...
CVE-2024-8464HIGH7.5SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /j...
CVE-2024-8463HIGH8.8File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an auth...
CVE-2024-8462MEDIUM6.3A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of...
CVE-2024-8461MEDIUM5.3A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part ...
CVE-2024-7884HIGH7.5When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the calle...
CVE-2024-8460MEDIUM5.9A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i...
CVE-2024-7605MEDIUM4.3The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-7381MEDIUM5.3The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization a...
CVE-2024-7380MEDIUM4.3The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c...
CVE-2024-5957HIGH7.5This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
CVE-2024-5956MEDIUM5.3This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the ...
CVE-2024-6929MEDIUM5.4The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ param...
CVE-2024-6894MEDIUM5.4The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5...
CVE-2024-6332MEDIUM6.5The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unaut...
CVE-2024-8363MEDIUM5.4The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shor...
CVE-2024-5309MEDIUM5.4The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modifi...
CVE-2024-45107MEDIUM5.5Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After F...
CVE-2024-6835MEDIUM5.3The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now