2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56195MEDIUM6.3Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 th...
CVE-2024-38311MEDIUM6.3Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ...
CVE-2024-56202MEDIUM4.3Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0....
CVE-2024-13902MEDIUM5.4A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown ...
CVE-2024-13897MEDIUM6.5The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2024-13868MEDIUM6.1The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an...
CVE-2024-57174HIGH8.1A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the de...
CVE-2024-51144HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_d...
CVE-2024-48246MEDIUM5.4Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /veh...
CVE-2024-31525HIGH7.2Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to eleva...
CVE-2024-53458HIGH7.5Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packe...
CVE-2024-11035LOW2.5Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a ty...
CVE-2024-12799CRITICAL10Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 b...
CVE-2024-13147CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2...
CVE-2024-12097CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat...
CVE-2024-11216HIGH7.6Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vuln...
CVE-2024-13471HIGH7.5The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2024-13423MEDIUM5.3The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capabili...
CVE-2024-12650MEDIUM5.4An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memo...
CVE-2024-12281CRITICAL9.8The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is...
CVE-2024-11951CRITICAL9.8The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including...
CVE-2024-11153MEDIUM5.3The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin...
CVE-2024-5667MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js Ja...
CVE-2024-13839MEDIUM6.1The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-13815MEDIUM6.5The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now