2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7925HIGH7.5A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of...
CVE-2024-7924HIGH7.5A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of th...
CVE-2024-43281MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Element...
CVE-2024-43280MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issu...
CVE-2024-43272MEDIUM5.3Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properl...
CVE-2024-43271HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Produc...
CVE-2024-43261CRITICAL9.6Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-43256HIGH7.1Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Pr...
CVE-2024-43252CRITICAL9Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a...
CVE-2024-43250MEDIUM6.5Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Co...
CVE-2024-43249HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This iss...
CVE-2024-43248CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro al...
CVE-2024-43247HIGH8.8Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by AC...
CVE-2024-43245CRITICAL9.8Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch...
CVE-2024-43242CRITICAL10Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue aff...
CVE-2024-43401HIGH8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without ...
CVE-2024-43400MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ...
CVE-2024-43240CRITICAL9.8Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultim...
CVE-2024-43236MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issu...
CVE-2024-43232HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essent...
CVE-2024-43221HIGH8.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilde...
CVE-2024-42658CRITICAL9.8An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-42657HIGH7.5An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-37099CRITICAL9.8Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: ...
CVE-2024-32928MEDIUM5.9The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which ena...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now