2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41305MEDIUM4.7A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application t...
CVE-2024-41304MEDIUM5.4An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execut...
CVE-2024-7297HIGH8.8Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged...
CVE-2024-7209MEDIUM6.5A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use net...
CVE-2024-7208MEDIUM6.5A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain,...
CVE-2024-5486MEDIUM4.9A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ...
CVE-2024-41944MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplay...
CVE-2024-41916MEDIUM4.9A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ...
CVE-2024-41915HIGH8.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at...
CVE-2024-41804MEDIUM6.5Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS...
CVE-2024-41803MEDIUM4.9Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM...
CVE-2024-41802HIGH8.1Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM...
CVE-2024-4188HIGH7.1Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This ...
CVE-2024-41109MEDIUM6.5Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` wi...
CVE-2024-39320MEDIUM6.1Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to...
CVE-2024-37299HIGH7.5Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long t...
CVE-2024-37165MEDIUM6.1Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could ...
CVE-2024-38909CRITICAL9.8Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension betwee...
CVE-2024-23091HIGH7.5Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwor...
CVE-2024-6699CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic...
CVE-2024-7127MEDIUM6.1Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cro...
CVE-2024-41702CRITICAL9.8SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-41701MEDIUM5.3AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-7226HIGH8.8A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulne...
CVE-2024-7225MEDIUM5.4A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now