2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3753MEDIUM5.9The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-3751MEDIUM4.8The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which c...
CVE-2024-3710MEDIUM6.8The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcod...
CVE-2024-3632MEDIUM6.8The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, whi...
CVE-2024-3026MEDIUM5.4The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which...
CVE-2024-2870MEDIUM6.1The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting...
CVE-2024-31947MEDIUM6.5StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a c...
CVE-2024-30213HIGH8.8StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injecti...
CVE-2024-5902MEDIUM6.1The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2024-40690MEDIUM5.4IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb...
CVE-2024-40110CRITICAL9.8Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability...
CVE-2024-40552HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray param...
CVE-2024-40551HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at...
CVE-2024-40550HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302....
CVE-2024-40549HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a...
CVE-2024-40548HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack...
CVE-2024-40547MEDIUM6.5PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component ...
CVE-2024-40546HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke...
CVE-2024-40545HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att...
CVE-2024-40544HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#mainten...
CVE-2024-40543HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?...
CVE-2024-40542CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40541CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40540CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40539CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now