2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31842HIGH8.8An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user ...
CVE-2024-42619HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-38175HIGH8.8An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta...
CVE-2024-6322MEDIUM5.4Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user...
CVE-2024-42612HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen...
CVE-2024-35214HIGH7.1A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3....
CVE-2024-43408MEDIUM6.3Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in ...
CVE-2024-42919CRITICAL9.8eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
CVE-2024-42598MEDIUM6.7SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplay...
CVE-2024-40743MEDIUM6.1The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
CVE-2024-27187HIGH7.5Improper Access Controls allows backend users to overwrite their username when disallowed.
CVE-2024-27186MEDIUM6.1The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVE-2024-27185CRITICAL9.1The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
CVE-2024-27184MEDIUM6.1Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
CVE-2024-43409MEDIUM6.5Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al...
CVE-2024-43406HIGH8.8LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev...
CVE-2024-43404CRITICAL9.8MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT version...
CVE-2024-43397MEDIUM4.3Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that al...
CVE-2024-43377MEDIUM4.3Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1....
CVE-2024-43376MEDIUM5.3Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is...
CVE-2024-42662HIGH7.5An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVE-2024-42621HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php
CVE-2024-42618HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karm...
CVE-2024-42617HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php...
CVE-2024-42616HIGH8.8Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.ph...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now