2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6733HIGH8.8A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this i...
CVE-2024-6732HIGH8.8A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. This...
CVE-2024-6731HIGH8.8A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0....
CVE-2024-39734MEDIUM4.3IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or...
CVE-2024-39733MEDIUM5.5IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be rea...
CVE-2024-39732HIGH7.5IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that cou...
CVE-2024-6730MEDIUM6.3A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This is...
CVE-2024-6729HIGH8.8A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been declared as c...
CVE-2024-6728CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affe...
CVE-2024-6465MEDIUM4.3The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-6574MEDIUM5.3The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This ...
CVE-2024-6070MEDIUM4.8The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its setti...
CVE-2024-5744MEDIUM6.8The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it...
CVE-2024-5715HIGH7.1The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5713MEDIUM5.4The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] pa...
CVE-2024-5644MEDIUM5.4The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-5627MEDIUM5.4The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with...
CVE-2024-5575MEDIUM4.7The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow h...
CVE-2024-5472HIGH7.1The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-5450CRITICAL9.1The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an un...
CVE-2024-5442MEDIUM5.9The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its setti...
CVE-2024-5287HIGH7.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, wh...
CVE-2024-5286MEDIUM4.8The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-5284MEDIUM6.8The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-5283MEDIUM6.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it ba...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now