2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43926MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver ...
CVE-2024-45056MEDIUM5.9zksolc is a Solidity compiler for ZKsync. All LLVM versions since 2015 fold `(xor (shl 1, x), -1)` to `(rotl ~1, x)` if ...
CVE-2024-45045MEDIUM6.1Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) dev...
CVE-2024-44919MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute ar...
CVE-2024-43804HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi...
CVE-2024-41964HIGH8.1Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o...
CVE-2024-35133HIGH8.2IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph...
CVE-2024-8255CRITICAL9.8Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through...
CVE-2024-43965CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGr...
CVE-2024-43957HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ...
CVE-2024-43955HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil...
CVE-2024-43954MEDIUM6.3Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T...
CVE-2024-43944LOW3.7Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-com...
CVE-2024-43943HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-35118MEDIUM4.6IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical a...
CVE-2024-8304MEDIUM4.9A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an un...
CVE-2024-8303MEDIUM6.3A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. T...
CVE-2024-43942HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-43941CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovo...
CVE-2024-43940MEDIUM6.5Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr...
CVE-2024-43939MEDIUM6.5Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr...
CVE-2024-43931CRITICAL9.8Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch...
CVE-2024-43922CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injectio...
CVE-2024-43918CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Ta...
CVE-2024-43917CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders T...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now