2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36691MEDIUM6.3Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbi...
CVE-2024-36265CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec...
CVE-2024-34065HIGH8.1Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session to...
CVE-2024-31217MEDIUM6.5Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen...
CVE-2024-2300MEDIUM6.2HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an ou...
CVE-2024-29181LOW3.5Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where...
CVE-2024-28964HIGH7.8Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A...
CVE-2024-5891MEDIUM4.2A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth tok...
CVE-2024-36699Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-36264CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do...
CVE-2024-36263HIGH8.1** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul...
CVE-2024-23445MEDIUM6.5It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security...
CVE-2024-1659CRITICAL9.8Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH...
CVE-2024-1577CRITICAL9.8Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring...
CVE-2024-1576CRITICAL9.8SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces...
CVE-2024-5313MEDIUM6.5CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product networ...
CVE-2024-25949HIGH8.8Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln...
CVE-2024-5211HIGH7.2A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function,...
CVE-2024-5056MEDIUM6.5CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the d...
CVE-2024-5674MEDIUM6.5The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH...
CVE-2024-4898CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due ...
CVE-2024-3492MEDIUM5.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-1766MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all ...
CVE-2024-4845HIGH8.8The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all vers...
CVE-2024-2092MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now