2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2098HIGH7.5The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization ...
CVE-2024-38295CRITICAL9.8ALCASAR before 3.6.1 allows still_connected.php remote code execution.
CVE-2024-38294CRITICAL9.8ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.
CVE-2024-38293CRITICAL9.6ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
CVE-2024-3922CRITICAL9.8The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in...
CVE-2024-4201MEDIUM4.4A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all ...
CVE-2024-1963MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16...
CVE-2024-1736MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions prior to 16.10.7, starting from 16.11 prior to 16.11...
CVE-2024-1495MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.1 prior to 16.10.7, starting from 1...
CVE-2024-3468HIGH8.4There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment un...
CVE-2024-3467HIGH7.8There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System ...
CVE-2024-37665HIGH8.8An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator vi...
CVE-2024-36523MEDIUM6.5An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after d...
CVE-2024-5798HIGH7.5Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the V...
CVE-2024-31881MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-5559MEDIUM6.8CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, devic...
CVE-2024-37629MEDIUM6.1SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.
CVE-2024-2747HIGH7.8CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation ...
CVE-2024-28762MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic...
CVE-2024-24051MEDIUM5.5Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the devi...
CVE-2024-0865HIGH7.8CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in a...
CVE-2024-5909MEDIUM5.5A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privile...
CVE-2024-5908HIGH7.5A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for c...
CVE-2024-5907HIGH7A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local ...
CVE-2024-5906MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious admin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now