2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-54106HIGH7.5Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-54105HIGH7.5Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-54104HIGH7.5Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability...
CVE-2024-54103HIGH7.5Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may a...
CVE-2024-54100HIGH7.5Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-54099HIGH7.1File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integri...
CVE-2024-54098HIGH7.5Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may...
CVE-2024-54097HIGH7.5Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature imp...
CVE-2024-11274HIGH8.7An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 pr...
CVE-2024-12397HIGH7.4A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming ...
CVE-2024-12312HIGH8.1The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...
CVE-2024-12172HIGH7.5The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress...
CVE-2024-12040HIGH8.8The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion i...
CVE-2024-10499HIGH7.2The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint b...
CVE-2024-10910HIGH7.3The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_p...
CVE-2024-10590HIGH8.8The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2024-11689HIGH8.8The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-11443HIGH8.8The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal...
CVE-2024-10111HIGH8.1The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all version...
CVE-2024-55658HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint...
CVE-2024-55657HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists i...
CVE-2024-54529HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS ...
CVE-2024-54528HIGH7.1A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, ...
CVE-2024-54515HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may b...
CVE-2024-54514HIGH8.6The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now