2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7246MEDIUM5.3It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the ba...
CVE-2024-33981MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke...
CVE-2024-33980MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke...
CVE-2024-33979MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke...
CVE-2024-33978MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially...
CVE-2024-33977MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially...
CVE-2024-33976MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne...
CVE-2024-33975MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne...
CVE-2024-33959HIGH7.5SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could explo...
CVE-2024-33958HIGH7.5SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by s...
CVE-2024-33957HIGH7.5SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by s...
CVE-2024-41995HIGH7.5Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If ...
CVE-2024-7084MEDIUM4.8The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow user...
CVE-2024-7082MEDIUM6.1The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allo...
CVE-2024-7055HIGH8.8A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decod...
CVE-2024-6766MEDIUM5.4The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes ...
CVE-2024-6651MEDIUM6.1The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it b...
CVE-2024-6203HIGH8.1HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links ...
CVE-2024-6202CRITICAL9.8HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML in...
CVE-2024-6201MEDIUM5.3HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate em...
CVE-2024-6200MEDIUM5.4HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScri...
CVE-2024-5709HIGH8.8The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-5708MEDIUM5.4The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter ...
CVE-2024-7506HIGH8.8A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by t...
CVE-2024-39817MEDIUM6.5Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now