2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6742MEDIUM5.4AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regul...
CVE-2024-6289MEDIUM6.1The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect W...
CVE-2024-6076MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6075HIGH8.8The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could all...
CVE-2024-6074MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6073MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin...
CVE-2024-6072MEDIUM6.1The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter bef...
CVE-2024-5630HIGH8.8The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading...
CVE-2024-21513HIGH8.5Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution ...
CVE-2024-6739MEDIUM6.1The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote att...
CVE-2024-6738MEDIUM5.3The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers t...
CVE-2024-6737HIGH8.8The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implement...
CVE-2024-39741MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the...
CVE-2024-39740MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all...
CVE-2024-39735MEDIUM5.4IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2024-39729MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive inform...
CVE-2024-39739MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF). This ma...
CVE-2024-39737MEDIUM5.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive informatio...
CVE-2024-39736CRITICAL9.8IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper v...
CVE-2024-39731HIGH7.5IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that coul...
CVE-2024-39728MEDIUM5.4IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerabi...
CVE-2024-6736HIGH8.8A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as crit...
CVE-2024-6345HIGH8.8A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution vi...
CVE-2024-6735HIGH8.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulner...
CVE-2024-6734HIGH8.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now