2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7925 | HIGH | 7.5 | 0.6% | Aug 19, 2024 | A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of... |
| CVE-2024-7924 | HIGH | 7.5 | 1.4% | Aug 19, 2024 | A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of th... |
| CVE-2024-43281 | MEDIUM | 5.3 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Element... |
| CVE-2024-43280 | MEDIUM | 6.1 | 0.2% | Aug 19, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issu... |
| CVE-2024-43272 | MEDIUM | 5.3 | 0.4% | Aug 19, 2024 | Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properl... |
| CVE-2024-43271 | HIGH | 8.5 | 0.6% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Produc... |
| CVE-2024-43261 | CRITICAL | 9.6 | 0.5% | Aug 19, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-43256 | HIGH | 7.1 | 0.4% | Aug 19, 2024 | Missing Authorization vulnerability in nouthemes Leopard - WordPress offload media allows Accessing Functionality Not Pr... |
| CVE-2024-43252 | CRITICAL | 9 | 0.4% | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a... |
| CVE-2024-43250 | MEDIUM | 6.5 | 0.3% | Aug 19, 2024 | Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Co... |
| CVE-2024-43249 | HIGH | 8.8 | 1.0% | Aug 19, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This iss... |
| CVE-2024-43248 | CRITICAL | 9.1 | 0.6% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro al... |
| CVE-2024-43247 | HIGH | 8.8 | 0.4% | Aug 19, 2024 | Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by AC... |
| CVE-2024-43245 | CRITICAL | 9.8 | 0.5% | Aug 19, 2024 | Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch... |
| CVE-2024-43242 | CRITICAL | 10 | 0.5% | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue aff... |
| CVE-2024-43401 | HIGH | 8 | 0.6% | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without ... |
| CVE-2024-43400 | MEDIUM | 5.4 | 0.5% | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ... |
| CVE-2024-43240 | CRITICAL | 9.8 | 0.5% | Aug 19, 2024 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultim... |
| CVE-2024-43236 | MEDIUM | 4.7 | 0.3% | Aug 19, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issu... |
| CVE-2024-43232 | HIGH | 8.5 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essent... |
| CVE-2024-43221 | HIGH | 8.5 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilde... |
| CVE-2024-42658 | CRITICAL | 9.8 | 1.4% | Aug 19, 2024 | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2024-42657 | HIGH | 7.5 | 0.5% | Aug 19, 2024 | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2024-37099 | CRITICAL | 9.8 | 0.6% | Aug 19, 2024 | Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: ... |
| CVE-2024-32928 | MEDIUM | 5.9 | 0.2% | Aug 19, 2024 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which ena... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now