2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4655MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputt...
CVE-2024-1845HIGH8.8The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, whic...
CVE-2024-22280HIGH8.1VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authent...
CVE-2024-6554MEDIUM5.3The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclos...
CVE-2024-6397CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all ...
CVE-2024-0619MEDIUM5.3The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-6676HIGH8.8A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by ...
CVE-2024-6210MEDIUM5.3The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. T...
CVE-2024-23485MEDIUM4.6Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the C...
CVE-2024-23317MEDIUM6.3External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local ...
CVE-2024-23194LOW3.3Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker...
CVE-2024-22387MEDIUM6.8External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface al...
CVE-2024-40618CRITICAL9.6Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when pr...
CVE-2024-6653CRITICAL9.8A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability af...
CVE-2024-6447HIGH7.2The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in a...
CVE-2024-6652HIGH8.8A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an...
CVE-2024-6650MEDIUM4.8A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problema...
CVE-2024-6037CRITICAL9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc...
CVE-2024-6036CRITICAL9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending ...
CVE-2024-39565HIGH8.8An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juni...
CVE-2024-39562HIGH8.7A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH da...
CVE-2024-39561MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Jun...
CVE-2024-39560HIGH7.1An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju...
CVE-2024-39559HIGH8.2An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS ...
CVE-2024-39558HIGH7.1An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Ne...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now