2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39649MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent...
CVE-2024-39648MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter...
CVE-2024-39637MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through...
CVE-2024-39636HIGH8.3Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and R...
CVE-2024-38761HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issu...
CVE-2024-32931MEDIUM5.7Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
CVE-2024-32865HIGH7.3Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected dev...
CVE-2024-32862HIGH8.1Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
CVE-2024-32758HIGH7.5Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient ke...
CVE-2024-7367HIGH8.8A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This ...
CVE-2024-7366CRITICAL9.8A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critica...
CVE-2024-7093CRITICAL9.4Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within ...
CVE-2024-41259CRITICAL9.1Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's...
CVE-2024-39634HIGH8.8Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issu...
CVE-2024-39633HIGH8.8Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This iss...
CVE-2024-39630MEDIUM5.5Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This i...
CVE-2024-39624HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ...
CVE-2024-39621HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ...
CVE-2024-39619CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ...
CVE-2024-38791HIGH7.1Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request For...
CVE-2024-38775HIGH7.2Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Fee...
CVE-2024-38772MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets fo...
CVE-2024-38770CRITICAL9.8Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation...
CVE-2024-38768HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elemen...
CVE-2024-38746HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeSto...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now