2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43165MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allow...
CVE-2024-43160CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP:...
CVE-2024-43153CRITICAL9.8Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <...
CVE-2024-43141CRITICAL9.8Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Inj...
CVE-2024-43140HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstr...
CVE-2024-43138HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Ma...
CVE-2024-37287HIGH7.2A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector ...
CVE-2024-35124HIGH7.5A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020...
CVE-2024-43135HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allow...
CVE-2024-43131HIGH7.5Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing ...
CVE-2024-43129HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs a...
CVE-2024-43128HIGH7.3Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Li...
CVE-2024-43121HIGH7.2Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: fr...
CVE-2024-41774MEDIUM4.8IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to em...
CVE-2024-40697HIGH7.5IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for ...
CVE-2024-39651CRITICAL9.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vo...
CVE-2024-39642MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality No...
CVE-2024-38787HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers i...
CVE-2024-38760MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Access...
CVE-2024-38756MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functi...
CVE-2024-38752MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campai...
CVE-2024-38749HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import all...
CVE-2024-38747HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Paym...
CVE-2024-38742MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Access...
CVE-2024-38724HIGH7.1Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scrip...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now